org.webjars:angular-sanitize@1.2.15 vulnerabilities

  • latest version

    1.3.11

  • first published

    11 years ago

  • latest version published

    10 years ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.webjars:angular-sanitize package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Incomplete Filtering of Special Elements

    org.webjars:angular-sanitize is an AngularJS module for sanitizing HTML

    Affected versions of this package are vulnerable to Incomplete Filtering of Special Elements through the ngSanitize module. An attacker can manipulate image sources and perform content spoofing by injecting malicious URLs into the 'href' and 'xlink:href' attributes of '' SVG elements.

    Note:

    The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status.

    How to fix Incomplete Filtering of Special Elements?

    There is no fixed version for org.webjars:angular-sanitize.

    [1.0.7,)