漏洞信息详情
AngularJS 输入验证错误漏洞
漏洞简介
AngularJS是一款基于TypeScript的开源Web应用程序框架。
AngularJS 1.7.9之前版本中存在输入验证错误漏洞。攻击者可借助‘merge()’函数利用该漏洞实施原型污染攻击。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/angular/angular.js/commit/add78e62004e80bb1e16ab2dfe224afa8e513bc3
参考网址
来源:MISC
链接:https://snyk.io/vuln/SNYK-JS-ANGULAR-534884
来源:MLIST
链接:https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4243
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4242
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4690/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/AngularJS-privilege-escalation-via-Object-prototype-merge-31166
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-10768
来源:www.us-cert.gov
链接:https://www.us-cert.gov/ics/advisories/icsa-20-133-02
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.1679/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-appliance-is-affected-by-multiple-angularjs-vulnerabilities/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-planning-analytics-workspace-is-affected-by-security-vulnerabilities-3/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-angularjs/
受影响实体
暂无
补丁
- AngularJS 输入验证错误漏洞的修复措施<!--2019-11-19-->
还没有评论,来说两句吧...