Angular-CLI Authentication Bypass

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Vulnerability summary The following advisory describes an athentication bypass vulnerability found in Angular-CLI version 1.3.2 The Angular CLI makes “it easy to create an application that already works, right out of the box. It already follows our best practices!” ### Credit An independent security researcher, Paolo Stagno aka VoidSec, has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program. ### Vendor response Angular-CLI was informed of the vulnerability, to which they response with: “This is a known ‘problem’, and people are using that feature quite extensively. Please note that we write a large warning message when users are running serve in production mode, and it is not a supported use case. The assumption that we are making (and maybe we could be clearer about it) is that you always run your development server (which is what ng serve is) in a local development environment, on a computer that’s firewalled properly from the internet. We...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息