arabaske / Ceres

0 stars 0 forks source link

CVE-2022-25869 (Medium) detected in angular-1.6.8.tgz #158

Open mend-bolt-for-github[bot] opened 2 years ago

mend-bolt-for-github[bot] commented 2 years ago

CVE-2022-25869 - Medium Severity Vulnerability

Vulnerable Library - angular-1.6.8.tgz

HTML enhanced for web apps

Library home page: https://registry.npmjs.org/angular/-/angular-1.6.8.tgz

Path to dependency file: /Ceres/package.json

Path to vulnerable library: /node_modules/angular/package.json

Dependency Hierarchy: - angular-trix-1.0.2.tgz (Root Library) - :x: **angular-1.6.8.tgz** (Vulnerable Library)

Found in HEAD commit: b31d728670f7b1cea140b9a346bf71d1a9771fb2

Found in base branch: clean_branch

Vulnerability Details

All versions of package angular are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of