Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runtime in @angular/core and @angular/compiler could omit or select an incorrect sanitizer for security-sensitive directive host bindings because SecurityContext was derived from the declaring directive or component selector rather than the concrete host element. The mismatch is reachable through hostDire
Remediation
References
Related Vulnerabilities
SharePoint CVE-2024-38227 Vulnerability (CVE-2024-38227)
Oracle Database Server CVE-2009-1020 Vulnerability (CVE-2009-1020)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2019-17267)
Python Integer Overflow or Wraparound Vulnerability (CVE-2022-37454)
WordPress Plugin Ajax BootModal Login Security Bypass (1.4.3)