Information on source package angular.js

Available versions

ReleaseVersion
bullseye1.8.2-2
bullseye (security)1.8.3-1+deb12u1~deb11u1
bookworm1.8.3-1
trixie1.8.3-3
forky1.8.3-3
sid1.8.3-3

Open issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2025-2336fixedvulnerable (no DSA, postponed)fixedfixedfixedImproper sanitization of the value of the 'href' and 'xlink:href' attr ...
CVE-2025-0716fixedvulnerable (no DSA, postponed)fixedfixedfixedImproper sanitization of the value of the 'href' and 'xlink:href' attr ...
CVE-2024-21490fixedvulnerable (no DSA, postponed)fixedfixedfixedThis affects versions of the package angular from 1.3.0. A regular exp ...
CVE-2024-8373fixedvulnerable (no DSA, postponed)fixedfixedfixedImproper sanitization of the value of the [srcset] attribute in <sourc ...
CVE-2024-8372fixedvulnerable (no DSA, postponed)fixedfixedfixedImproper sanitization of the value of the 'srcset' attribute in Angula ...
CVE-2023-26118fixedvulnerable (no DSA, postponed)fixedfixedfixedVersions of the package angular from 1.4.9 are vulnerable to Regular E ...
CVE-2023-26117fixedvulnerable (no DSA, postponed)fixedfixedfixedVersions of the package angular from 1.0.0 are vulnerable to Regular E ...
CVE-2023-26116fixedvulnerable (no DSA, postponed)fixedfixedfixedVersions of the package angular from 1.2.21 are vulnerable to Regular ...
CVE-2022-25869vulnerable (no DSA)vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerablevulnerableAll versions of the package angular; all versions of the package angul ...
CVE-2022-25844fixedvulnerable (no DSA, postponed)fixedfixedfixedThe package angular after 1.7.0 are vulnerable to Regular Expression D ...

Resolved issues

BugDescription
CVE-2020-7676angular.js prior to 1.8.0 allows cross site scripting. The regex-based ...
CVE-2019-14863There is a vulnerability in all angular versions before 1.5.0-beta.0, ...
CVE-2019-10768In AngularJS before 1.7.9 the function `merge()` could be tricked into ...

Security announcements

DSA / DLADescription
DLA-4242-1angular.js - security update
DLA-1995-1angular.js - security update

Search for package or bug name: Reporting problems