Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing .

This issue affects all versions of AngularJS.

Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4242-1 angular.js security update
EUVD EUVD EUVD-2024-2837 Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Github GHSA Github GHSA GHSA-mqm9-c95h-x2p6 AngularJS allows attackers to bypass common image source restrictions
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Apr 2025 06:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Wed, 12 Feb 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Netapp
Netapp active Iq Unified Manager
CPEs cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
Vendors & Products Netapp
Netapp active Iq Unified Manager

Fri, 22 Nov 2024 13:00:00 +0000

Type Values Removed Values Added
References

Tue, 17 Sep 2024 18:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-Other

Mon, 09 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Description Improper sanitization of the value of the '[srcset]' attribute in '<source>' HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status . Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
First Time appeared Angularjs
Angularjs angular.js
CPEs cpe:2.3:a:angularjs:angular.js:*:*:*:*:*:*:*:*
Vendors & Products Angularjs
Angularjs angular.js
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
Description Improper sanitization of the value of the '[srcset]' attribute in '<source>' HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Title AngularJS improper sanitization in '<source>' element
Weaknesses CWE-791
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HeroDevs

Published:

Updated: 2025-05-28T17:39:12.299Z

Reserved: 2024-09-02T08:44:29.571Z

Link: CVE-2024-8373

cve-icon Vulnrichment

Updated: 2024-11-22T12:04:52.671Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-09T15:15:12.887

Modified: 2025-02-12T20:15:05.360

Link: CVE-2024-8373

cve-icon Redhat

Severity : Low

Publid Date: 2024-09-09T15:15:12Z

Links: CVE-2024-8373 - Bugzilla

cve-icon OpenCVE Enrichment

No data.