PT-2023-21727 · Unknown · Angular-Server-Side-Configuration

Milo526

·

Publicado

2023-03-24

·

Atualizado

2023-04-03

·

CVE-2023-28444

CVSS v3.1

9.9

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions angular-server-side-configuration versions 15.0.0 through 15.0.x
Description The issue concerns the detection of environment variables in TypeScript files during the build time of an Angular CLI project. These variables are written to a ngssc.json file and later inserted into the app's index.html file. In a monorepo setup, this could lead to the exposure of environment variables intended for a backend or service via index.html. This has no impact on plain Angular projects without a backend component.
Recommendations For angular-server-side-configuration versions 15.0.0 through 15.0.x, update to version 15.1.0, which adds an option searchPattern to restrict the detection file range by default. Alternatively, manually edit or create ngssc.json, or run a script after ngssc.json generation as a temporary workaround.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28444
GHSA-GWVM-VRP4-4PP5

Produtos afetados

Angular-Server-Side-Configuration