CVE-2024-8372
CVE-2024-8372 is a medium-severity vulnerability in Angularjs with a CVSS 3.x base score of 4.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1289.
Key facts
- Severity: Medium (CVSS 3.x base score 4.8)
- EPSS exploit prediction: 1% (47th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-2834
- Weakness: CWE-1289
- Affected product: Angularjs
- Published:
- Last modified:
Description
Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Frequently asked questions
- What is CVE-2024-8372?
- Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
- How severe is CVE-2024-8372?
- CVE-2024-8372 has a CVSS 3.x base score of 4.8, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability low.
- Is CVE-2024-8372 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (47th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-8372?
- CVE-2024-8372 primarily affects Angularjs. In total, 6 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2024-8372?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-8372 have an EU (EUVD) identifier?
- Yes. CVE-2024-8372 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-2834.
- When was CVE-2024-8372 published?
- CVE-2024-8372 was published on 2024-09-09 and last updated on 2026-06-17.
References
- https://codepen.io/herodevs/full/xxoQRNL/0072e627abe03e9cda373bc75b4c1017
- https://www.herodevs.com/vulnerability-directory/cve-2024-8372
- https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html
- https://security.netapp.com/advisory/ntap-20241122-0002/
Affected products (6)
- cpe:2.3:a:angularjs:angularjs:*:*:*:*:*:*:*:*
- cpe:2.3:a:angularjs:angularjs:1.3.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:angularjs:angularjs:1.3.0:rc5:*:*:*:*:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
More vulnerabilities in Angularjs
- CVE-2019-10768 — High (CVSS 7.5): In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of…
- CVE-2019-14863 — Medium (CVSS 6.1): There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web…
- CVE-2020-7676 — Medium (CVSS 5.4): angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code…
- CVE-2023-26118 — Medium (CVSS 5.3): Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the…
- CVE-2023-26117 — Medium (CVSS 5.3): Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the…
- CVE-2023-26116 — Medium (CVSS 5.3): Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the…
All CVEs affecting Angularjs →
Other CWE-1289 vulnerabilities
- CVE-2026-39821 — Critical (CVSS 9.6): The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For…
- CVE-2026-50090 — Critical (CVSS 9.3): The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due…
- CVE-2024-42219 — High (CVSS 7.8): 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process…
- CVE-2026-60074 — High (CVSS 7.5): Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric…
- CVE-2026-49942 — High (CVSS 7.3): Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could…
- CVE-2024-45179 — High (CVSS 7.2): An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input…