Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-25869 (Medium) detected in angular-1.5.0.js #1906

Closed
mend-for-github-com bot opened this issue Jul 17, 2022 · 4 comments · Fixed by #5086
Closed

CVE-2022-25869 (Medium) detected in angular-1.5.0.js #1906

mend-for-github-com bot opened this issue Jul 17, 2022 · 4 comments · Fixed by #5086
Labels
cve Security vulnerabilities detected by Dependabot or Mend de-angular de-angularize work dependencies Pull requests that update a dependency file medium severity Medium severity CVE Mend: dependency security vulnerability Security vulnerability detected by Mend v2.11.0

Comments

@mend-for-github-com
Copy link

mend-for-github-com bot commented Jul 17, 2022

CVE-2022-25869 - Medium Severity Vulnerability

Vulnerable Library - angular-1.5.0.js

AngularJS is an MVC framework for building web applications. The core features include HTML enhanced with custom component and data-binding capabilities, dependency injection and strong focus on simplicity, testability, maintainability and boiler-plate reduction.

Library home page: https://cdnjs.cloudflare.com/ajax/libs/angular.js/1.5.0/angular.js

Path to dependency file: /node_modules/ui-select/docs-out/demo-tagging.html

Path to vulnerable library: /node_modules/ui-select/docs-out/demo-tagging.html,/node_modules/ui-select/docs-built/demo-object-as-source.html,/node_modules/ui-select/docs/index.html

Dependency Hierarchy:

  • angular-1.5.0.js (Vulnerable Library)

Found in base branch: main

Vulnerability Details

All versions of package angular are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

Publish Date: 2022-07-15

URL: CVE-2022-25869

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

@mend-for-github-com mend-for-github-com bot added the Mend: dependency security vulnerability Security vulnerability detected by Mend label Jul 17, 2022
@kavilla
Copy link
Member

kavilla commented Jul 24, 2022

Will get resolved with this: #1558

@kavilla kavilla marked this as a duplicate of #1558 Jul 24, 2022
@kavilla kavilla closed this as completed Jul 24, 2022
@kavilla kavilla reopened this Jul 24, 2022
@kavilla kavilla added medium severity Medium severity CVE cve Security vulnerabilities detected by Dependabot or Mend labels Aug 17, 2022
@CCongWang
Copy link
Contributor

what is the suggested fix?? upgrade to which version? @kavilla

@seraphjiang
Copy link
Member

what is the suggested fix?? upgrade to which version? @kavilla
i believe the plan is to remove angular from osd

@zhongnansu zhongnansu added the de-angular de-angularize work label Nov 14, 2022
@joshuarrrr joshuarrrr added the dependencies Pull requests that update a dependency file label Jan 11, 2023
@mend-for-github-com mend-for-github-com bot changed the title CVE-2022-25869 (Medium) detected in angular-1.8.2.tgz CVE-2022-25869 (Medium) detected in angular-1.5.0.js, angular-1.8.2.tgz Aug 14, 2023
@mend-for-github-com mend-for-github-com bot changed the title CVE-2022-25869 (Medium) detected in angular-1.5.0.js, angular-1.8.2.tgz CVE-2022-25869 (Medium) detected in angular-1.5.0.js Sep 29, 2023
@ashwin-pc
Copy link
Member

closed by #5086

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cve Security vulnerabilities detected by Dependabot or Mend de-angular de-angularize work dependencies Pull requests that update a dependency file medium severity Medium severity CVE Mend: dependency security vulnerability Security vulnerability detected by Mend v2.11.0
Projects
Development

Successfully merging a pull request may close this issue.

6 participants