CVE-2023-26117: Medium severity angularjs vulnerability
All versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Other sources
CVE-2019-10768 In AngularJS before 1.7.9 the function merge() could be tricked into adding or modifying properties of Object.prototype using a proto payload. CVE-2023-26116 Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
— F5
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-26117.
What package is affected by this vulnerability?
The package affected by this vulnerability is Angularjs Angular.
What is the severity of CVE-2023-26117?
The severity of CVE-2023-26117 is medium with a CVSS score of 5.3.
How can the vulnerability be exploited?
The vulnerability can be exploited by using a large carefully-crafted input, resulting in catastrophic backtracking.
Are there any references available for further information?
Yes, you can refer to the following links: [link1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/), [link2](https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406323), [link3](https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406325).