CVE-2024-8373
CVE-2024-8373 is a medium-severity vulnerability in Angularjs with a CVSS 3.x base score of 4.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-791.
Key facts
- Severity: Medium (CVSS 3.x base score 4.8)
- EPSS exploit prediction: 1% (48th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-2837
- Weakness: CWE-791
- Affected product: Angularjs
- Published:
- Last modified:
Description
Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Frequently asked questions
- What is CVE-2024-8373?
- Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
- How severe is CVE-2024-8373?
- CVE-2024-8373 has a CVSS 3.x base score of 4.8, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability low.
- Is CVE-2024-8373 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (48th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-8373?
- CVE-2024-8373 primarily affects Angularjs. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2024-8373?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-8373 have an EU (EUVD) identifier?
- Yes. CVE-2024-8373 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-2837.
- When was CVE-2024-8373 published?
- CVE-2024-8373 was published on 2024-09-09 and last updated on 2026-06-17.
References
- https://codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0b
- https://www.herodevs.com/vulnerability-directory/cve-2024-8373
- https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html
- https://security.netapp.com/advisory/ntap-20241122-0003/
Affected products (4)
- cpe:2.3:a:angularjs:angularjs:*:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
More vulnerabilities in Angularjs
- CVE-2019-10768 — High (CVSS 7.5): In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of…
- CVE-2019-14863 — Medium (CVSS 6.1): There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web…
- CVE-2020-7676 — Medium (CVSS 5.4): angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code…
- CVE-2023-26118 — Medium (CVSS 5.3): Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the…
- CVE-2023-26117 — Medium (CVSS 5.3): Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the…
- CVE-2023-26116 — Medium (CVSS 5.3): Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the…
All CVEs affecting Angularjs →
Other CWE-791 vulnerabilities
- CVE-2025-0324 — Critical (CVSS 9.4): The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to…
- CVE-2024-47590 — High (CVSS 8.8): An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated…
- CVE-2026-44232 — High (CVSS 8.7): DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.3,…
- CVE-2022-2132 — High (CVSS 8.6): A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of…
- CVE-2024-45481 — High (CVSS 8.5): An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may…
- CVE-2026-11998 — High (CVSS 7.6): A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and…