Asymmetric denial of service - ReDoS In angular
Description
angular vulnerable to regular expression denial of service via the $resource service All versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | - | ||
debian 12 | 1.8.3-1+deb12u1 | ||
debian 13 | 1.8.3-2 | ||
debian 11 | 1.8.3-1+deb12u1~deb11u1 | ||
rpm rhel8 | - | - | |
rpm rhel6 | - | - | |
rpm rhel9 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.