Skip to content

Denial of Service and Content Injection in i18n-node-angular

High severity GitHub Reviewed Published Feb 18, 2019 to the GitHub Advisory Database • Updated Feb 1, 2023

Package

npm i18n-node-angular (npm)

Affected versions

< 1.4.0

Patched versions

1.4.0

Description

Versions of i18n-node-angular prior to 1.4.0 are affected by denial of service and cross-site scripting vulnerabilities. The vulnerabilities exist in a REST endpoint that was created for development purposes, but was not disabled in production in affected versions.

Recommendation

Update to version 1.4.0 or later.

References

Published by the National Vulnerability Database May 31, 2018
Published to the GitHub Advisory Database Feb 18, 2019
Reviewed Jun 16, 2020
Last updated Feb 1, 2023

Severity

High
8.2
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
High
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H

CVE ID

CVE-2016-10524

GHSA ID

GHSA-97gv-3p2c-xw7j
Checking history
See something to contribute? Suggest improvements for this vulnerability.