
We found results for “”
CVE-2023-26117
Good to know:

Date: March 30, 2023
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Language: JS
Severity Score
Related Resources (10)
Severity Score
Weakness Type (CWE)
Inefficient Regular Expression Complexity
CWE-1333Top Fix

Upgrade Version
Upgrade to version angular - 1.9.7;angular - 1.5.23;angular-i18n - 1.9.7-i18n;angular-i18n - 1.5.23-i18n;angular-loader - 1.5.23-loader;angular-loader - 1.9.7-loader;angular-cookies - 1.9.7-cookies;angular-cookies - 1.5.23-cookies;angular-message-format - 1.9.7-message-format;angular-message-format - 1.5.23-message-format;angular-route - 1.5.23-route;angular-route - 1.9.7-route;angular-sanitize - 1.5.23-sanitize;angular-sanitize - 1.9.7-sanitize;angular-mocks - 1.9.7-mocks;angular-mocks - 1.5.23-mocks;angular-aria - 1.5.23-aria;angular-aria - 1.9.7-aria;angular-resource - 1.5.23-resource;angular-resource - 1.9.7-resource;angular-parse-ext - 1.9.7-parse-ext;angular-parse-ext - 1.5.23-parse-ext;angular-messages - 1.5.23-messages;angular-messages - 1.9.7-messages;angular-animate - 1.5.23-animate;angular-animate - 1.9.7-animate;angular-touch - 1.9.7-touch;angular-touch - 1.5.23-touch;angular - 1.5.23;angular - 1.9.7;angular-cookies - 1.9.7-cookies;angular-cookies - 1.5.23-cookies;angular-touch - 1.5.23-touch;angular-touch - 1.9.7-touch;angular-parse-ext - 1.5.23-parse-ext;angular-parse-ext - 1.9.7-parse-ext;angular-loader - 1.9.7-loader;angular-loader - 1.5.23-loader;angular-sanitize - 1.9.7-sanitize;angular-sanitize - 1.5.23-sanitize;angular-aria - 1.5.23-aria;angular-aria - 1.9.7-aria;angular-messages - 1.5.23-messages;angular-messages - 1.9.7-messages;angular-message-format - 1.5.23-message-format;angular-message-format - 1.9.7-message-format;angular-mocks - 1.5.23-mocks;angular-mocks - 1.9.7-mocks;angular-i18n - 1.5.23-i18n;angular-i18n - 1.9.7-i18n;angular-animate - 1.9.7-animate;angular-animate - 1.5.23-animate;angular-route - 1.9.7-route;angular-route - 1.5.23-route;angular-resource - 1.5.23-resource;angular-resource - 1.9.7-resource
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | LOW |