lukebrogan-mend / Umbraco-CMS

The simple, flexible and friendly ASP.NET CMS used by more than 500.000 websites
https://umbraco.com
MIT License
0 stars 0 forks source link

CVE-2022-25844 (High) detected in angular-1.8.0.tgz - autoclosed #268

Closed mend-for-github-com[bot] closed 1 year ago

mend-for-github-com[bot] commented 2 years ago

CVE-2022-25844 - High Severity Vulnerability

Vulnerable Library - angular-1.8.0.tgz

HTML enhanced for web apps

Library home page: https://registry.npmjs.org/angular/-/angular-1.8.0.tgz

Path to dependency file: /src/Umbraco.Web.UI.Client/package.json

Path to vulnerable library: /src/Umbraco.Web.UI.Client/node_modules/angular/package.json

Dependency Hierarchy: - :x: **angular-1.8.0.tgz** (Vulnerable Library)

Found in base branch: v8/contrib

Vulnerability Details

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.

Publish Date: 2022-05-01

URL: CVE-2022-25844

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

mend-for-github-com[bot] commented 1 year ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.