Executive brief
i18n-node-angular is a Node.js library that provides internationalization support for Angular applications. Versions prior to 1.4.0 contain a development-only REST endpoint that was inadvertently exposed in production, allowing unauthenticated attackers to trigger denial of service or inject malicious content into the application.
Technical details
The vulnerability exists in a REST endpoint (/i18n/:locale/:phrase) that was intended exclusively for development purposes but was not properly gated by environment checks in affected versions. This endpoint was exposed in production environments, allowing attackers with low privileges and user interaction to perform denial of service attacks (CWE-400) and cross-site scripting attacks via content injection (CWE-74). The fix conditionally registers the vulnerable route only when NODE_ENV is set to "development", preventing the endpoint from being accessible in production deployments. Patch version 1.4.0 or later resolves the issue.
Affected products
- Oliver Salzburg i18n-node-angular <1.4.0
Timeline
- 2018-05-31: disclosed
- 2019-02-18: advisory
- 2016: patched: Fix commit available; version 1.4.0 or later