ionic-team / ionic-v1

The repo for Ionic 1.x. For the latest version of Ionic, please see https://github.com/ionic-team/ionic
Other
192 stars 187 forks source link

Client_DOM_Code_Injection Security issuse in lib\ionic\js\ionic.bundle.js #269

Open rainmakerho opened 7 years ago

rainmakerho commented 7 years ago

We are using ionic and found that it is having security issue Client_DOM_Code_Injection in lib\ionic\js\ionic.bundle.js when scanned using checkmarx security tool.

Details:

Source: /lib/ionic/js/ionic.bundle.js $state.transitionTo(state, $match, { inherit: true, location: false });

  1. $state.transitionTo(state, $match, { inherit: true,location: false });

Sink: /lib/ionic/js/ionic.bundle.js $urlRouterProvider.when(state.url, ['$match', '$stateParams', function ($match, $stateParams) {

/lib/ionic/js/ionic.bundle.js function registerState(state) {

  1. $urlRouterProvider.when(state.url, ['$match','$stateParams', function ($match, $stateParams) {

Thanks for your help.