Versions of angular
prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize xlink:href
attributes, which may allow attackers to execute arbitrary JavaScript in a victim's browser if the value is user-controlled.
Upgrade to version 1.5.0-beta.1 or later.
{ "github_reviewed": true, "severity": "MODERATE", "nvd_published_at": "2020-01-02T15:15:00Z", "cwe_ids": [ "CWE-79" ], "github_reviewed_at": "2020-02-13T17:26:17Z" }