A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication first. Upgrading to version 11.0.5 and 11.1.0-next.3 is able to address this issue. The name of the patch is ba8da742e3b243e8f43d4c63aa842b44e14f2b09. It is recommended to upgrade the affected component.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade cephadm-ansibleUpgrade libcephfs2-debuginfoUpgrade ceph-fuseUpgrade ceph-radosgw-debuginfoUpgrade rbd-mirror-debuginfoUpgrade ceph-immutable-object-cacheUpgrade python3-cephfs-debuginfoUpgrade ceph-exporter-debuginfoUpgrade ceph-immutable-object-cache-debuginfoUpgrade python3-radosUpgrade python3-ceph-commonUpgrade cephfs-topUpgrade libradosstriper1Upgrade ceph-mds-debuginfoUpgrade ceph-osd-debuginfoUpgrade ceph-common-debuginfoUpgrade cephfs-mirror-debuginfoUpgrade rbd-fuse-debuginfoUpgrade cephadmUpgrade python3-rbd-debuginfoUpgrade librbd-develUpgrade ansible-collection-ansible-posixUpgrade libcephfs-develUpgrade rbd-nbdUpgrade python3-rgwUpgrade librgw2-debuginfoUpgrade librgw-develUpgrade ceph-test-debuginfoUpgrade ceph-mon-debuginfoUpgrade ceph-debuginfoUpgrade python3-rbdUpgrade librgw2Upgrade python3-rados-debuginfoUpgrade python3-ceph-argparseUpgrade librados-develUpgrade ceph-commonUpgrade libradospp-develUpgrade python3-rgw-debuginfoUpgrade python3-cephfsUpgrade libcephfs2Upgrade libcephsqlite-debuginfoUpgrade ceph-baseUpgrade rbd-nbd-debuginfoUpgrade librados-devel-debuginfoUpgrade ceph-fuse-debuginfoUpgrade ceph-base-debuginfoUpgrade ceph-resource-agentsUpgrade ceph-selinuxUpgrade ceph-mibUpgrade ceph-mgr-debuginfoUpgrade libradosstriper1-debuginfoUpgrade ceph-debugsource | Jun 16, 2023 | May 26, 2022 |
| Redhat_linux | — | Upgrade python3-rbd-debuginfoUpgrade libradosstriper1-debuginfoUpgrade libcephfs2-debuginfoUpgrade ansible-collection-ansible-posixUpgrade libcephfs-develUpgrade ceph-immutable-object-cacheUpgrade rbd-fuse-debuginfoUpgrade librados-devel-debuginfoUpgrade ceph-debuginfoUpgrade librgw2-debuginfoUpgrade librados-develUpgrade cephfs-mirror-debuginfoUpgrade ceph-commonUpgrade ceph-mds-debuginfoUpgrade libcephsqlite-debuginfoUpgrade rbd-nbdUpgrade librgw-develUpgrade ceph-fuse-debuginfoUpgrade ceph-immutable-object-cache-debuginfoUpgrade python3-ceph-commonUpgrade python3-radosUpgrade libcephfs2Upgrade rbd-nbd-debuginfoUpgrade ceph-radosgw-debuginfoUpgrade python3-rgwUpgrade python3-cephfsUpgrade ceph-baseUpgrade ceph-mibUpgrade rbd-mirror-debuginfoUpgrade python3-cephfs-debuginfoUpgrade ceph-common-debuginfoUpgrade ceph-mgr-debuginfoUpgrade ceph-selinuxUpgrade cephadmUpgrade ceph-exporter-debuginfoUpgrade python3-rgw-debuginfoUpgrade cephadm-ansibleUpgrade ceph-osd-debuginfoUpgrade libradosstriper1Upgrade ceph-debugsourceUpgrade python3-ceph-argparseUpgrade python3-rados-debuginfoNo solution existsUpgrade ceph-fuseUpgrade libradospp-develUpgrade librgw2Upgrade librbd-develUpgrade ceph-resource-agentsUpgrade python3-rbdUpgrade cephfs-topUpgrade ceph-base-debuginfoUpgrade ceph-mon-debuginfoUpgrade ceph-test-debuginfo | Jun 16, 2023 | May 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub