CVE-2017-16009: XSS
Published Jun 4, 2018
·Updated
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
Affected Software
2 affected components
ag-grid ag-grid<27.0.0
angularjs AngularJS<1.6
Event History
Jun 4, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-16009?
CVE-2017-16009 is a vulnerability in ag-grid that allows for Cross-site Scripting (XSS) attacks if AngularJS is used in combination with ag-grid.
2
How does CVE-2017-16009 affect ag-grid?
CVE-2017-16009 affects ag-grid by enabling Cross-site Scripting (XSS) attacks when AngularJS is used in conjunction with ag-grid.
3
What is the severity of CVE-2017-16009?
CVE-2017-16009 has a severity level of medium with a severity value of 6.1.
4
How can I fix CVE-2017-16009?
To fix CVE-2017-16009, update ag-grid to version 27.0.0 or higher.
5
Is AngularJS vulnerable to CVE-2017-16009?
No, AngularJS is not vulnerable to CVE-2017-16009.