CVE-2019-14863

NameCVE-2019-14863
DescriptionThere is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1995-1
NVD severitymedium
Debian Bugs942833

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
angular.js (PTS)buster, stretch1.5.10-1fixed
bullseye, sid1.8.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
angular.jssource(unstable)1.5.3-2942833
angular.jssourcejessie1.2.26-1+deb8u1DLA-1995-1

Notes

https://snyk.io/vuln/npm:angular:20150807
https://github.com/angular/angular.js/commit/f33ce173c90736e349cf594df717ae3ee41e0f7a
https://github.com/angular/angular.js/pull/12524

Search for package or bug name: Reporting problems