CVE-2021-4231

3.5 LOW
Published: May 26, 2022 Modified: November 20, 2025

Description

A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication first. Upgrading to version 11.0.5 and 11.1.0-next.3 is able to address this issue. The name of the patch is ba8da742e3b243e8f43d4c63aa842b44e14f2b09. It is recommended to upgrade the affected component.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/angular/angular/issues/40136
Source: cna@vuldb.com
Third Party Advisory
https://security.snyk.io/vuln/SNYK-JS-ANGULARCORE-1070902
Source: cna@vuldb.com
Third Party Advisory
https://vuldb.com/?id.181356
Source: cna@vuldb.com
Third Party Advisory
https://github.com/angular/angular/commit/ba8da742e3b243e8f43d4c63aa842b44e14f2b09
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
https://github.com/angular/angular/issues/40136
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://security.snyk.io/vuln/SNYK-JS-ANGULARCORE-1070902
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://vuldb.com/?id.181356
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
3.5 / 10.0
EPSS (Exploit Probability)
1.3%
80th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

angular angularjs