CVE-2024-21490P3HIGHCVSS 7.5≥ 1.3.02024-02-10
CVE-2024-21490 [HIGH] CWE-1333 CVE-2024-21490: This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note
nvdosv