GHSA-r3hf-q8q7-fv2p

Suggest an improvement
Source
https://github.com/advisories/GHSA-r3hf-q8q7-fv2p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-r3hf-q8q7-fv2p/GHSA-r3hf-q8q7-fv2p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r3hf-q8q7-fv2p
Published
2023-08-09T12:51:51Z
Modified
2023-08-09T12:51:51Z
Summary
Angular critical CSS inlining Cross-site Scripting Vulnerability Advisory
Details

Impact

Angular Universal applications on 16.1.0 and 16.1.1 using critical CSS inlining are vulnerable to a cross-site scripting (XSS) attack where an attacker can trick another user into visiting a page which injects malicious JavaScript.

Angular CLI applications without Universal do perform critical CSS inlining as well, however exploiting this requires a malicious actor to already have access to modify source code directly.

Patches

@nguniversal/common should be upgraded to 16.1.2 or higher. 16.2.0-rc.0 is safe.

Workarounds

The easiest solution is likely to upgrade Universal to 16.1.2 or downgrade to 16.0.x or lower. Alternatively you can override specifically the critters dependency with version 0.0.20 in your package.json.

{
  "overrides": {
    "critters": "0.0.20"
  }
}

References

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-08-09T12:51:51Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / @nguniversal/common

Package

Name
@nguniversal/common
View open source insights on deps.dev
Purl
pkg:npm/%40nguniversal/common

Affected ranges

Type
SEMVER
Events
Introduced
16.1.0
Fixed
16.1.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-r3hf-q8q7-fv2p/GHSA-r3hf-q8q7-fv2p.json"