VYPR
Medium severity4.8NVD Advisory· Published Sep 9, 2024· Updated Jun 17, 2026

CVE-2024-8372

CVE-2024-8372

Description

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing .

This issue affects AngularJS versions 1.3.0-rc.4 and greater.

Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
angularnpm
>= 1.3.0-rc.4, <= 1.8.3

Affected products

12
  • Google/AngularJSv5
    Range: >=1.3.0-rc.4
  • ghsa-coords5 versions
    >= 1.3.0-rc.4, <= 1.8.3+ 4 more
    • (no CPE)range: >= 1.3.0-rc.4, <= 1.8.3
    • (no CPE)range: < 9.8.1-r0
    • (no CPE)range: < 9.8.1-r0
    • (no CPE)range: < 9.8.1-r0
    • (no CPE)range: < 9.8.1-r0
  • cpe:2.3:a:angularjs:angularjs:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:angularjs:angularjs:*:*:*:*:*:*:*:*range: >=1.3.1,<=1.8.3
    • cpe:2.3:a:angularjs:angularjs:1.3.0:rc4:*:*:*:*:*:*
    • cpe:2.3:a:angularjs:angularjs:1.3.0:rc5:*:*:*:*:*:*
  • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.