compiler is vulnerable to Cross-Site Scripting (XSS)
85
High Risk
Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) via SVG animation attributeName and MathML/SVG URLs, where SVG animation elements could be exploited to modify the href or xlink:href attributes of other elements to malicious javascript: URLs, allowing an attacker to execute arbitrary JavaScript code by tricking a user into viewing a crafted SVG document.
You are affected if you are using a version that falls within the vulnerable range.
compiler is vulnerable to Cross-Site Scripting (XSS) in versions 19.0.0 - 21.0.1.
Upgrade the org.mvnpm.at.angular:compiler library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant