Medium severity6.1NVD Advisory· Published Jan 2, 2020· Updated Jun 17, 2026
CVE-2019-14863
CVE-2019-14863
Description
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
angularnpm | < 1.5.0-beta.1 | 1.5.0-beta.1 |
Affected products
5- Red Hat/angular:v5Range: all angular versions before 1.5.0-beta.0
- cpe:2.3:a:redhat:decision_manager:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- snyk.io/vuln/npm:angular:20150807nvdPatchThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-r5fx-8r73-v86cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-14863ghsaADVISORY
- github.com/angular/angular.js/commit/35a21532b73d5bd84b4325211c563e6a3e2dde82ghsaWEB
- github.com/angular/angular.js/commit/f33ce173c90736e349cf594df717ae3ee41e0f7aghsaWEB
- github.com/angular/angular.js/pull/12524ghsaWEB
- www.npmjs.com/advisories/1453ghsaWEB
News mentions
0No linked articles in our index yet.