Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing .

This issue affects AngularJS versions 1.3.0-rc.4 and greater.

Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4242-1 angular.js security update
EUVD EUVD EUVD-2024-2834 Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Github GHSA Github GHSA GHSA-m9gf-397r-hwpg AngularJS allows attackers to bypass common image source restrictions
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Apr 2025 06:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Mon, 28 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Description Improper sanitization of the value of the '[srcset]' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status . Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

Wed, 12 Feb 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Netapp
Netapp active Iq Unified Manager
CPEs cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
Vendors & Products Netapp
Netapp active Iq Unified Manager

Fri, 22 Nov 2024 13:00:00 +0000

Type Values Removed Values Added
References

Tue, 17 Sep 2024 17:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:angularjs:angular.js:1.3.0:rc4:*:*:*:*:*:*
cpe:2.3:a:angularjs:angular.js:1.3.0:rc5:*:*:*:*:*:*

Mon, 09 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Angularjs
Angularjs angular.js
CPEs cpe:2.3:a:angularjs:angular.js:*:*:*:*:*:*:*:*
Vendors & Products Angularjs
Angularjs angular.js
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
Description Improper sanitization of the value of the '[srcset]' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Title AngularJS improper sanitization in 'srcset' attribute
Weaknesses CWE-1289
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HeroDevs

Published:

Updated: 2025-05-28T17:39:48.004Z

Reserved: 2024-09-02T08:44:11.786Z

Link: CVE-2024-8372

cve-icon Vulnrichment

Updated: 2024-11-22T12:04:51.702Z

cve-icon NVD

Status : Modified

Published: 2024-09-09T15:15:12.560

Modified: 2025-04-28T14:15:20.107

Link: CVE-2024-8372

cve-icon Redhat

Severity : Low

Publid Date: 2024-09-09T15:15:12Z

Links: CVE-2024-8372 - Bugzilla

cve-icon OpenCVE Enrichment

No data.