Cross-site scripting in AngularJS - CVE-2020-7676

 

Cross-site scripting in AngularJS - CVE-2020-7676

Published: June 16, 2020


Vulnerability identifier: #VU29032
CSH Severity: Low
CVSS v4 BT: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear]
CVE-ID: CVE-2020-7676
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when wrapping "<option>" elements in "<select>" ones changes parsing behavior. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

AngularJS
IBM Security Verify Information Queue
Planning Analytics Cartridge for Cloud Pak for Data
IBM Business Automation Manager Open Editions
IBM Planning Analytics Workspace
IBM Cloud Pak for Watson AIOps
Storage Protect Plus Server
IBM Cloud Automation Manager
IBM Guardium Data Encryption (GDE)
IBM Transformation Extender Advanced
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
BIG-IQ Centralized Management
IBM DataPower Gateway
F5 SSL Orchestrator
HPE Unified OSS Console (UOC)
Red Hat Single Sign-On
rh-sso7-keycloak (Red Hat package)
Dell Storage Manager

How to mitigate CVE-2020-7676

Install updates from vendor's website.

AngularJS - update to 1.8.0
IBM Business Automation Manager Open Editions - update to 8.0.8
IBM DataPower Gateway - addressed in versions 10.0.1.4, 10.0.3.0, 2018.4.1.17
IBM Planning Analytics Workspace - update to 2.0.84
HPE Unified OSS Console (UOC) - update to 3.1.8
IBM Cloud Pak for Watson AIOps - update to 4.1
IBM Guardium Data Encryption (GDE) - update to 5.0.0.0
Red Hat Single Sign-On - update to 7.4.6
rh-sso7-keycloak (Red Hat package) - addressed in versions 9.0.12-1.redhat_00001.1.el6sso, 9.0.12-1.redhat_00001.1.el7sso, 9.0.12-1.redhat_00001.1.el8sso
IBM Transformation Extender Advanced - addressed in versions 10.0.1.11, 10.0.2.0
IBM Spectrum Protect Plus - update to 10.1.6.4
Storage Protect Plus Server - update to 10.1.16.3
IBM Business Automation Workflow - addressed in versions 21.0.3 IF021, 22.0.2 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.21, 22.0.2.5
Dell Storage Manager - update to 2020 R1.21

External References

Related Security Bulletins