CVE-2024-8372
Last modified
CVE-2024-8372 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Angularjs | Angularjs | >= 1.3.1, <= 1.8.3 | — |
| Angularjs | Angularjs | 1.3.0 | Rc4 |
| Netapp | Active Iq Unified Manager | All versions | — |
References
- https://codepen.io/herodevs/full/xxoQRNL/0072e627abe03e9cda373bc75b4c1017Exploit, Third Party Advisory
- https://www.herodevs.com/vulnerability-directory/cve-2024-8372Exploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20241122-0002/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-8372?
How severe is CVE-2024-8372?
How do I fix CVE-2024-8372?
Are you affected by CVE-2024-8372?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
