QID 981957

QID 981957: Nodejs (npm) Security Update for angular (GHSA-89mq-4x47-5v83)

Versions of `angular ` prior to 1.7.9 are vulnerable to prototype pollution. The deprecated API function `merge()` does not restrict the modification of an Object's prototype in the , which may allow an attacker to add or modify an existing property that will exist on all objects.




## Recommendation

Upgrade to version 1.7.9 or later. The function was already deprecated and upgrades are not expected to break functionality.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-89mq-4x47-5v83 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981957

    Software Advisories
    Advisory ID Software Component Link
    GHSA-89mq-4x47-5v83 angular URL Logo github.com/advisories/GHSA-89mq-4x47-5v83