VYPR

Maven package

org.webjars.bower/angular

pkg:maven/org.webjars.bower/angular

Vulnerabilities (1)

  • CVE-2024-21490Feb 10, 2024
    affected >= 1.3.0, <= 1.8.3

    This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a