ZeroHour

CVE-2019-14863

CVSS 3.1
6.1 medium
EPSS
1%p71
Published
()
Modified
Description

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Vendors
angularjsredhat
Products
angularjs, decision manager, process automation
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.