This issue affects AngularJS versions 1.3.0-rc.4 and greater.
Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4242-1 | angular.js security update |
EUVD |
EUVD-2024-2834 | Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status . |
Github GHSA |
GHSA-m9gf-397r-hwpg | AngularJS allows attackers to bypass common image source restrictions |
Ubuntu USN |
USN-7958-1 | AngularJS vulnerabilities |
Thu, 20 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Angularjs angularjs
|
|
| CPEs | cpe:2.3:a:angularjs:angular.js:1.3.0:rc5:*:*:*:*:*:* |
cpe:2.3:a:angularjs:angularjs:*:*:*:*:*:*:*:* cpe:2.3:a:angularjs:angularjs:1.3.0:rc4:*:*:*:*:*:* cpe:2.3:a:angularjs:angularjs:1.3.0:rc5:*:*:*:*:*:* |
| Vendors & Products |
Angularjs angularjs
|
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 29 Apr 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 28 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper sanitization of the value of the '[srcset]' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status . | Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status . |
Wed, 12 Feb 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp active Iq Unified Manager |
|
| CPEs | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Netapp
Netapp active Iq Unified Manager |
Fri, 22 Nov 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 17 Sep 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:angularjs:angular.js:1.3.0:rc4:*:*:*:*:*:* cpe:2.3:a:angularjs:angular.js:1.3.0:rc5:*:*:*:*:*:* |
Mon, 09 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Angularjs
Angularjs angular.js |
|
| CPEs | cpe:2.3:a:angularjs:angular.js:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Angularjs
Angularjs angular.js |
|
| Metrics |
ssvc
|
Mon, 09 Sep 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper sanitization of the value of the '[srcset]' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status . | |
| Title | AngularJS improper sanitization in 'srcset' attribute | |
| Weaknesses | CWE-1289 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HeroDevs
Published:
Updated: 2025-11-03T19:34:58.181Z
Reserved: 2024-09-02T08:44:11.786Z
Link: CVE-2024-8372
Updated: 2024-11-22T12:04:51.702Z
Status : Modified
Published: 2024-09-09T15:15:12.560
Modified: 2025-11-20T18:00:14.787
Link: CVE-2024-8372
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN