CVE-2022-25869 (Medium) detected in angular-1.5.0.js #1906
Labels
cve
Security vulnerabilities detected by Dependabot or Mend
de-angular
de-angularize work
dependencies
Pull requests that update a dependency file
medium severity
Medium severity CVE
Mend: dependency security vulnerability
Security vulnerability detected by Mend
v2.11.0
CVE-2022-25869 - Medium Severity Vulnerability
AngularJS is an MVC framework for building web applications. The core features include HTML enhanced with custom component and data-binding capabilities, dependency injection and strong focus on simplicity, testability, maintainability and boiler-plate reduction.
Library home page: https://cdnjs.cloudflare.com/ajax/libs/angular.js/1.5.0/angular.js
Path to dependency file: /node_modules/ui-select/docs-out/demo-tagging.html
Path to vulnerable library: /node_modules/ui-select/docs-out/demo-tagging.html,/node_modules/ui-select/docs-built/demo-object-as-source.html,/node_modules/ui-select/docs/index.html
Dependency Hierarchy:
Found in base branch: main
All versions of package angular are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.
Publish Date: 2022-07-15
URL: CVE-2022-25869
Base Score Metrics:
The text was updated successfully, but these errors were encountered: