Source: angular.js X-Debbugs-CC: [email protected] Severity: important Tags: security
Hi, The following vulnerability was published for angular.js. CVE-2024-8373[0]: | Improper sanitization of the value of the [srcset] attribute in | <source> HTML elements in AngularJS allows attackers to bypass | common image source restrictions, which can also lead to a form of | Content Spoofing https://owasp.org/www- | community/attacks/Content_Spoofing . This issue affects all | versions of AngularJS. Note: The AngularJS project is End-of-Life | and will not receive any updates to address this issue. For more | information see here https://docs.angularjs.org/misc/version- | support-status . https://codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0b If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2024-8373 https://www.cve.org/CVERecord?id=CVE-2024-8373 Please adjust the affected versions in the BTS as needed.

