Back

MEDIUM

nodejs-angular: XSS due to regex-based HTML replacement

Published Jun 8, 2020

Description

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.

Affected products

Remediation

Red Hat statement

Quay does not contain the affected component usage.

Metrics

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Jun 8, 2020
Updated Aug 4, 2024
Reserved Jan 21, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 19, 2020
GHSA-MHP6-PXH8-R675