Medium severity4.8NVD Advisory· Published Sep 9, 2024· Updated Jun 17, 2026
CVE-2024-8373
CVE-2024-8373
Description
Improper sanitization of the value of the [srcset] attribute in HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing .
This issue affects all versions of AngularJS.
Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
angularnpm | <= 1.8.3 | — |
Affected products
10- osv-coords5 versionspkg:apk/chainguard/solrpkg:apk/chainguard/solr-oci-compatpkg:apk/wolfi/solrpkg:apk/wolfi/solr-oci-compatpkg:npm/angular
< 9.8.1-r0+ 4 more
- (no CPE)range: < 9.8.1-r0
- (no CPE)range: < 9.8.1-r0
- (no CPE)range: < 9.8.1-r0
- (no CPE)range: < 9.8.1-r0
- (no CPE)range: <= 1.8.3
- Google/AngularJSv5Range: >=0.0.0
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
Patches
Vulnerability mechanics
References
7- codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0bnvdExploitThird Party AdvisoryWEB
- www.herodevs.com/vulnerability-directory/cve-2024-8373nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-mqm9-c95h-x2p6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8373ghsaADVISORY
- security.netapp.com/advisory/ntap-20241122-0003/nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/07/msg00005.htmlnvdWEB
- security.netapp.com/advisory/ntap-20241122-0003ghsaWEB
News mentions
0No linked articles in our index yet.