You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.
i18n for your Angular apps, made easy
Library home page: https://cdnjs.cloudflare.com/ajax/libs/angular-translate/2.7.2/angular-translate.min.js
Path to vulnerable library: /rest-angular/src/main/webapp/js/lib/angular-translate.min.js
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - angular-translate-2.7.2.min.js
i18n for your Angular apps, made easy
Library home page: https://cdnjs.cloudflare.com/ajax/libs/angular-translate/2.7.2/angular-translate.min.js
Path to vulnerable library: /rest-angular/src/main/webapp/js/lib/angular-translate.min.js
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.
Publish Date: 2024-04-26
URL: CVE-2024-33665
CVSS 3 Score Details (5.5)
Base Score Metrics:
The text was updated successfully, but these errors were encountered: