The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade angular-server-side-configuration
to version 15.1.0 or higher.
angular-server-side-configuration is a Configure an angular application on the server
Affected versions of this package are vulnerable to Information Exposure. angular-server-side-configuration
detects used environment variables in TypeScript (.ts
) files during build time of an Angular CLI project. The detected environment variables are written to an ngssc.json
file in the output directory. During deployment of an Angular based app, the environment variables based on the variables from ngssc.json
are inserted into the app's index.html
(or defined index file).
In version 15.0.0 the environment variable detection was widened to the entire project, relative to the angular.json
file from the Angular CLI. In a monorepo setup, this could lead to environment variables intended for a backend/service to be detected and written to the ngssc.json
, which would then be populated and exposed via index.html
.
Note This has no impact in a plain Angular project that has no backend component.