U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-8373

Change History

New CVE Received by NIST 9/09/2024 11:15:12 AM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
HeroDevs AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Added CWE

								
							
							
						
HeroDevs CWE-791
Added Description

								
							
							
						
Improper sanitization of the value of the '[srcset]' attribute in '<source>' HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of  Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing .

This issue affects all versions of AngularJS.

Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see  here https://docs.angularjs.org/misc/version-support-status .
Added Reference

								
							
							
						
HeroDevs https://codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0b [No types assigned]
Added Reference

								
							
							
						
HeroDevs https://www.herodevs.com/vulnerability-directory/cve-2024-8373 [No types assigned]
Added Tag

								
							
							
						
HeroDevs unsupported-when-assigned