Skip to content

angular-translate-2.7.2.min.js: 1 vulnerabilities (highest severity is: 5.5) #13

@dev-mend-for-github-com

Description

@dev-mend-for-github-com
Vulnerable Library - angular-translate-2.7.2.min.js

i18n for your Angular apps, made easy

Library home page: https://cdnjs.cloudflare.com/ajax/libs/angular-translate/2.7.2/angular-translate.min.js

Path to vulnerable library: /rest-angular/src/main/webapp/js/lib/angular-translate.min.js

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in (angular-translate version) Remediation Possible** Reachability
CVE-2024-33665 Medium 5.5 angular-translate-2.7.2.min.js Direct N/A

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2024-33665

Vulnerable Library - angular-translate-2.7.2.min.js

i18n for your Angular apps, made easy

Library home page: https://cdnjs.cloudflare.com/ajax/libs/angular-translate/2.7.2/angular-translate.min.js

Path to vulnerable library: /rest-angular/src/main/webapp/js/lib/angular-translate.min.js

Dependency Hierarchy:

  • angular-translate-2.7.2.min.js (Vulnerable Library)

Found in base branch: master

Vulnerability Details

angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.

Publish Date: 2024-04-26

URL: CVE-2024-33665

CVSS 3 Score Details (5.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions