Vulnerability Description
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ag-Grid | Ag-Grid | < 27.0.0 |
| Angularjs | Angularjs | < 1.6 |
Related Weaknesses (CWE)
References
- https://github.com/ceolter/ag-grid/issues/1287Issue TrackingThird Party Advisory
- https://nodesecurity.io/advisories/327Broken LinkThird Party Advisory
- https://spring.io/blog/2016/01/28/angularjs-escaping-the-expression-sandbox-for-ExploitTechnical DescriptionThird Party Advisory
- https://github.com/ceolter/ag-grid/issues/1287Issue TrackingThird Party Advisory
- https://nodesecurity.io/advisories/327Broken LinkThird Party Advisory
- https://spring.io/blog/2016/01/28/angularjs-escaping-the-expression-sandbox-for-ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2017-16009?
CVE-2017-16009 is a vulnerability with a CVSS score of 6.1 (MEDIUM). ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
How severe is CVE-2017-16009?
CVE-2017-16009 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16009?
Check the references section above for vendor advisories and patch information. Affected products include: Ag-Grid Ag-Grid, Angularjs Angularjs.