A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication first. Upgrading to version 11.0.5 and 11.1.0-next.3 is able to address this issue. The name of the patch is ba8da742e3b243e8f43d4c63aa842b44e14f2b09. It is recommended to upgrade the affected component.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python3-rgw-debuginfoUpgrade libradosstriper1-debuginfoUpgrade ceph-baseUpgrade python3-cephfsUpgrade rbd-nbd-debuginfoUpgrade libradospp-develUpgrade ceph-debugsourceUpgrade libcephfs2Upgrade ceph-mibUpgrade ceph-selinuxUpgrade ceph-mgr-debuginfoUpgrade python3-rados-debuginfoUpgrade ceph-resource-agentsUpgrade librados-develUpgrade python3-ceph-argparseUpgrade ceph-debuginfoUpgrade librgw2-debuginfoUpgrade rbd-nbdUpgrade ceph-test-debuginfoUpgrade librados-devel-debuginfoUpgrade python3-rgwUpgrade ceph-mon-debuginfoUpgrade ceph-base-debuginfoUpgrade python3-rbdUpgrade librgw-develUpgrade ceph-fuse-debuginfoUpgrade librgw2Upgrade libcephfs-develUpgrade ceph-commonUpgrade libcephsqlite-debuginfoUpgrade ceph-common-debuginfoUpgrade cephfs-topUpgrade libradosstriper1Upgrade libcephfs2-debuginfoUpgrade cephadm-ansibleUpgrade rbd-mirror-debuginfoUpgrade python3-cephfs-debuginfoUpgrade ceph-exporter-debuginfoUpgrade ceph-radosgw-debuginfoUpgrade ceph-osd-debuginfoUpgrade ansible-collection-ansible-posixUpgrade cephadmUpgrade rbd-fuse-debuginfoUpgrade librbd-develUpgrade ceph-fuseUpgrade python3-ceph-commonUpgrade ceph-mds-debuginfoUpgrade python3-rbd-debuginfoUpgrade python3-radosUpgrade ceph-immutable-object-cache-debuginfoUpgrade ceph-immutable-object-cacheUpgrade cephfs-mirror-debuginfo | Jun 16, 2023 | May 26, 2022 |
| Redhat_linux | — | Upgrade rbd-nbdUpgrade python3-ceph-commonUpgrade ceph-debuginfoUpgrade python3-radosUpgrade librados-devel-debuginfoUpgrade ceph-immutable-object-cache-debuginfoUpgrade librados-develUpgrade python3-rbd-debuginfoUpgrade libcephfs2Upgrade libcephfs-develUpgrade librgw-develUpgrade libcephsqlite-debuginfoUpgrade ansible-collection-ansible-posixUpgrade ceph-fuse-debuginfoUpgrade rbd-fuse-debuginfoUpgrade libcephfs2-debuginfoUpgrade ceph-commonUpgrade ceph-mds-debuginfoUpgrade cephfs-mirror-debuginfoUpgrade librgw2-debuginfoUpgrade rbd-nbd-debuginfoUpgrade libradosstriper1-debuginfoUpgrade ceph-immutable-object-cacheUpgrade ceph-osd-debuginfoUpgrade python3-rgw-debuginfoUpgrade ceph-fuseUpgrade ceph-debugsourceNo solution existsUpgrade python3-cephfsUpgrade ceph-base-debuginfoUpgrade libradospp-develUpgrade ceph-resource-agentsUpgrade cephadm-ansibleUpgrade librgw2Upgrade python3-rbdUpgrade cephfs-topUpgrade python3-rados-debuginfoUpgrade librbd-develUpgrade ceph-selinuxUpgrade ceph-mon-debuginfoUpgrade python3-rgwUpgrade ceph-mgr-debuginfoUpgrade cephadmUpgrade ceph-baseUpgrade ceph-exporter-debuginfoUpgrade ceph-mibUpgrade python3-cephfs-debuginfoUpgrade ceph-test-debuginfoUpgrade ceph-radosgw-debuginfoUpgrade ceph-common-debuginfoUpgrade rbd-mirror-debuginfoUpgrade python3-ceph-argparseUpgrade libradosstriper1 | Jun 16, 2023 | May 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub