Junglewise Threat Intelligence

CVE-2024-21490: AngularJS regular expression denial of service in ng-srcset

CVE-2024-21490 · Severity: low · CVSS 3.1 · Published 2024-02-10

Technologies: angular (npm), AngularJS. Vendors: Maven, npm, Angular.

Executive brief

AngularJS is a widely-used JavaScript framework for building dynamic web applications. A vulnerability exists in how the framework parses image source attributes (ng-srcset directive) that can be exploited by sending specially-crafted input. An attacker can cause the application to consume excessive CPU resources and become unresponsive, denying service to legitimate users. Since AngularJS is no longer maintained, users must migrate to the modern @angular/core framework for a fix.

Technical details

This vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in the regular expression used to split the ng-srcset directive value in AngularJS (CWE-1333). The vulnerable regex exhibits catastrophic backtracking behavior when processing specially-crafted input strings with repetitive patterns. An attacker can remotely trigger this vulnerability by injecting a malicious ng-srcset attribute value in a web page served by an AngularJS application; no authentication or user interaction is required. The attack causes the regex engine to perform an exponential number of backtracking operations, exhausting CPU resources and rendering the application unresponsive. The affected versions span from 1.3.0 to 1.8.3. Since AngularJS is end-of-life, no patches will be released; users must migrate to @angular/core.

Affected products

  • Angular AngularJS 1.3.0 to 1.8.3
  • npm angular 1.3.0 to 1.8.3
  • Webjars org.webjars.npm:angular 1.3.0 to 1.8.3
  • Webjars org.webjars.bower:angular 1.3.0 to 1.8.3

Timeline

  • 2023-11-28: disclosed: Vulnerability reported to Snyk
  • 2024-02-10: advisory: GHSA-4w4v-5hc9-xrr2 and CVE-2024-21490 published
  • 2024-04-12: other: AngularJS repository archived; package marked end-of-life

References

Related threats