V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-26116
DEB
Medium

Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility f…

CVSS
5.3
Medium
EPSS
0.02
p74
Published
2023-01-01
Updated
2023-01-01
Description

Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

Tags · CWE
Pre-auth
CWE-1333
CAPEC-492
Affected products
Angularjs 1.2.21–1.8.3
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.017 · p74
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angular.jsTracked
angularjs*Tracked
fedora*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities