{"id":"GHSA-28hp-fgcr-2r4h","summary":"Cross-Site Scripting via JSONP","details":"JSONP allows untrusted resource URLs, which provides a vector for attack by malicious actors.","modified":"2021-02-24T18:32:36Z","published":"2019-06-27T17:25:42Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2019-06-27T15:51:47Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/angular/angular.js/commit/6476af83cd0418c84e034a955b12a842794385c4"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1630"}],"affected":[{"package":{"name":"angular","ecosystem":"npm","purl":"pkg:npm/angular"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.6.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-28hp-fgcr-2r4h/GHSA-28hp-fgcr-2r4h.json"}}],"schema_version":"1.9.0"}