CVE-2019-14863
published 2020-01-02CVE-2019-14863: There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers…
PriorityP424medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.38%
69.1th percentile
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| angular | angular | >= 0 < 1.5.0-beta.1 | 1.5.0-beta.1 |
| angularjs | angularjs | 1.0.0 – 1.4.14 | — |
| debian | angular.js | < angular.js 1.5.3-2 (bookworm) | angular.js 1.5.3-2 (bookworm) |
| red_hat | angular | — | — |
| redhat | decision_manager | — | — |
| redhat | process_automation | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
angular.js vulnerabilities
osv·2026-01-14·CVSS 6.1
CVE-2019-14863 [MEDIUM] angular.js vulnerabilities
angular.js vulnerabilities
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of s
OSV
AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes
osv·2020-02-14
CVE-2019-14863 [MEDIUM] AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes
AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes
Versions of `angular` prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize `xlink:href` attributes, which may allow attackers to execute arbitrary JavaScript in a victim's browser if the value is user-controlled.
## Recommendation
Upgrade to version 1.5.0-beta.1 or later.
GHSA
AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes
ghsa·2020-02-14
CVE-2019-14863 [MEDIUM] CWE-79 AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes
AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes
Versions of `angular` prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize `xlink:href` attributes, which may allow attackers to execute arbitrary JavaScript in a victim's browser if the value is user-controlled.
## Recommendation
Upgrade to version 1.5.0-beta.1 or later.
OSV
CVE-2019-14863: There is a vulnerability in all angular versions before 1
osv·2020-01-02·CVSS 6.1
CVE-2019-14863 [MEDIUM] CVE-2019-14863: There is a vulnerability in all angular versions before 1
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Ubuntu
AngularJS vulnerabilities
vendor_ubuntu·2026-01-14·CVSS 6.1
CVE-2024-8372 [MEDIUM] AngularJS vulnerabilities
Title: AngularJS vulnerabilities
Summary: Several security issues were fixed in AngularJS.
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
Red Hat
angular: Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes
vendor_redhat·2019-10-15·CVSS 6.1
CVE-2019-14863 [MEDIUM] CWE-79 angular: Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes
angular: Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
A cross-site scripting (XSS) flaw was found in Angular. This flaw occurs due to improper sanitation of xlink:href attributes, which allows the web application to deliver data to users, along with other trusted content, without proper validation.
Debian
CVE-2019-14863: angular.js - There is a vulnerability in all angular versions before 1.5.0-beta.0, where afte...
vendor_debian·2019·CVSS 6.1
CVE-2019-14863 [MEDIUM] CVE-2019-14863: angular.js - There is a vulnerability in all angular versions before 1.5.0-beta.0, where afte...
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Scope: local
bookworm: resolved (fixed in 1.5.3-2)
bullseye: resolved (fixed in 1.5.3-2)
forky: resolved (fixed in 1.5.3-2)
sid: resolved (fixed in 1.5.3-2)
trixie: resolved (fixed in 1.5.3-2)
No detection rules found.
No public exploits indexed.
2020-01-02
Published