forked from Esri/esri.github.io
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
WS-2017-0121 - High Severity Vulnerability
Vulnerable Library - angular-1.2.30.tgz
HTML enhanced for web apps
Library home page: https://registry.npmjs.org/angular/-/angular-1.2.30.tgz
Path to dependency file: /tmp/ws-scm/esri.github.io/package.json
Path to vulnerable library: /esri.github.io/node_modules/angular/package.json,/esri.github.io/node_modules/angular/package.json
Dependency Hierarchy:
- ❌ angular-1.2.30.tgz (Vulnerable Library)
Found in HEAD commit: a4d59687db7452886288c3f1faa3a43e975f6ff8
Vulnerability Details
Affected versions of Angular.js are vulnerable to Arbitrary Code Execution via unsafe svg animation tags.
Publish Date: 2017-01-20
URL: WS-2017-0121
Suggested Fix
Type: Upgrade version
Origin: angular/angular.js#11290
Release Date: 2017-01-31
Fix Resolution: v1.4.0-beta.6
- Check this box to open an automated fix PR
Metadata
Metadata
Assignees
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource