Impact of jquery and angularjs vulnerabilities
search cancel

Impact of jquery and angularjs vulnerabilities

book

Article ID: 401503

calendar_today

Updated On: 07-02-2025

Products

VMware vSphere ESXi

Issue/Introduction

angularjs version 1.8.2, which has the following vulnerabilities:
End-of-Life: Long term support for AngularJS has been discontinued as of December 31, 2021

  • CVE-2024-8373: Image source sanitization bypass (a form of Content Spoofing)
  • CVE-2023-26117: angular vulnerable to regular expression denial of service via the $resource service
  • CVE-2023-26116: angular vulnerable to regular expression denial of service via the angular.copy() utility
  • CVE-2022-25869: Angular (deprecated package) Cross-site Scripting
  • CVE-2023-26118: angular vulnerable to regular expression denial of service via the <input> element
  • CVE-2024-21490: angular vulnerable to super-linear runtime due to backtracking
  • CVE-2022-25844: angular vulnerable to regular expression denial of service (ReDoS)

jquery version 2.2.0, which has the following vulnerabilities:
jQuery 1.x and 2.x are End-of-Life and no longer receiving security updates
CVE-2015-9251: 3rd party CORS request may execute

  • CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution
  • CVE-2020-11023: passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code.
  • CVE-2020-11022: Regex in its jQuery.htmlPrefilter sometimes may introduce XSS

Environment

  • 7.x
  • 8.x

Resolution

VMware By Broadcom is aware of the following CVEs related to angularjs and jquery.

CVE-2024-8373
CVE-2023-26116
CVE-2023-26117
CVE-2023-26118
CVE-2024-21490
CVE-2022-25844
CVE-2022-25869

CVE-2015-9251
CVE-2020-11022
CVE-2020-11023
CVE-2019-11358

Please refer to the release notes for existing and forthcoming product releases for any updates in relation to these CVEs.
Should you require further information please contact Broadcom Support.