ManageIQ / ManageIQ/ui-components

CVE-2023-26116 (Medium) detected in angular-1.8.3.tgz

Open
#474 4 comments 0 reactions 0 assignees View on GitHub
Mend: dependency security vulnerability stale
Dominant language
TypeScript
Stars
16
Forks
55
PR merge metrics
No merged PRs in 30d

Description

## CVE-2023-26116 - Medium Severity Vulnerability
Vulnerable Library - angular-1.8.3.tgz

HTML enhanced for web apps


Library home page: https://registry.npmjs.org/angular/-/angular-1.8.3.tgz


Sample Path to Dependency File: /package.json


Path to vulnerable library: /home/wss-scanner/.yarn/berry/cache/angular-npm-1.8.3-0e5e833690-10.zip


Dependency Hierarchy:
- angular-ui-sortable-0.19.0.tgz (Root Library)
- :x: **angular-1.8.3.tgz** (Vulnerable Library)

Found in HEAD commit: a5db0714038685437d759b29eb80b4b9e415b2c2


Found in base branch: master



Vulnerability Details



Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

Publish Date: 2023-03-30

URL: CVE-2023-26116



CVSS 3 Score Details (5.3)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low


For more information on CVSS3 Scores, click here.

***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

Open the contributing guide

Research direction

Start with package.json and inspect how angular-ui-sortable-0.19.0.tgz brings in angular-1.8.3.tgz. Identify a compatible non-vulnerable Angular dependency, then run the project's dependency or security checks to confirm CVE-2023-26116 is no longer reported.

Written by the indexing model from the issue text.

Assessment

Tech stack
angular
Domain
frontend, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.