Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a vulnerability was discovered in @angular/common when Server-Side Rendering (SSR) and hydration are enabled. The HttpTransferCache utility optimizes hydration by caching outgoing HTTP requests performed during SSR and transferring the cached state to the client-side application via TransferState. However, the caching mechanism fails to inspect the withCredentials flag or the Cookie header of outgoing requests. As a result, credentialed, user-specific responses may be cached by default in the shared TransferState payload. When these responses are serialized into the HTML, any caching layer (such as a CDN, reverse proxy, or shared server cache) that caches the SSR-rendered HTML page could inadvertently cache and leak one user's private data to other users, leading to a high-severity information disclosure vulnerability. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 18.2.14CPE matchmatch criteria | cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:* | ||
>= 19.0.0, < 19.2.23CPE matchmatch criteria | cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:* | ||
>= 20.0.0, < 20.3.22CPE matchmatch criteria | cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:* | ||
>= 21.0.0, < 21.2.15CPE matchmatch criteria | cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:* | ||
22.0.0CPE matchmatch criteria | cpe:2.3:a:angular:angular:22.0.0:next0:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.