Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RCE vulnerability in angular 1.5.5 (virtualan-plugin) #439

Open
4ndris opened this issue Aug 22, 2022 · 8 comments
Open

RCE vulnerability in angular 1.5.5 (virtualan-plugin) #439

4ndris opened this issue Aug 22, 2022 · 8 comments

Comments

@4ndris
Copy link

4ndris commented Aug 22, 2022

Security analysis of the current virtualan-plugin detects a vulnerability in the third party js library angular 1.5.5.
Nexus IQ identifies the threat with high-severity.

Issue
sonatype-2016-0064
Severity
Sonatype CVSS 38.5
CVE CVSS 2.00.0
Weakness
Sonatype CWE79

Explanation
The AngularJS framework is vulnerable to Remote Code Execution (RCE) and Cross-Site Scripting (XSS). The ensureSafeAssignContext() function in parse.js processes malicious expressions that access the constructors. A remote attacker can exploit this vulnerability by crafting malicious expressions that, when processed, result in execution of arbitrary code.

@elans3
Could you please review this? Thanks

@4ndris 4ndris changed the title RCE vulnerability in angular RCE vulnerability in angular 1.5.5 (virtualan-plugin) Aug 22, 2022
@4ndris
Copy link
Author

4ndris commented Aug 31, 2022

@elans3
Let me know if I can share any other detail that could help

@elans3
Copy link
Member

elans3 commented Sep 1, 2022

Identified the issue and will be working addressing the issue.

@4ndris Working on the fix will be released by next week.

@elans3
Copy link
Member

elans3 commented Oct 4, 2022

@4ndris this issue fixed in September release and version 2.5.3. Please confirm the same.

@4ndris
Copy link
Author

4ndris commented Oct 21, 2022

@elans3 I see version 2.5.3 still suffer from CVE-2022-42003
Beyond:

@elans3
Copy link
Member

elans3 commented Oct 21, 2022

@4ndris
I will start looking at the issue.
Can you share which security product that should i scan before I release?

@4ndris
Copy link
Author

4ndris commented Feb 8, 2023

Hi @elans3 , do you have any update regarding this? Nexus-IQ you can use to reproduce
Maybe any plan to replace this old version of angular?

@elans3
Copy link
Member

elans3 commented Feb 14, 2023

Thanks @4ndris . Working and Keep you updated. Will remove older version of Angular as well.

@elans3
Copy link
Member

elans3 commented Feb 26, 2024

I'm thrilled to announce that version 3.1.0 of the Virtualan plugin with Reactjs has been released, @4ndris. I took the liberty of removing the outdated AngularJS code. So, let's get excited and start using the latest and greatest version of the plugin!"

Thanks for the patience

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants