QID 981957
QID 981957: Nodejs (npm) Security Update for angular (GHSA-89mq-4x47-5v83)
Versions of `angular ` prior to 1.7.9 are vulnerable to prototype pollution. The deprecated API function `merge()` does not restrict the modification of an Object's prototype in the , which may allow an attacker to add or modify an existing property that will exist on all objects.
## Recommendation
Upgrade to version 1.7.9 or later. The function was already deprecated and upgrades are not expected to break functionality.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-89mq-4x47-5v83 for updates pertaining to this vulnerability.
Vendor References
- GHSA-89mq-4x47-5v83 -
github.com/advisories/GHSA-89mq-4x47-5v83
CVEs related to QID 981957
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-89mq-4x47-5v83 | angular |
|