Use of vulnerable component - Angular.js v1.5.8

Description

Currently, we are using the AngularJS framework in version 1.5.8 and this framework have a known security vulnerability which can render the application vulnerable to cross-site scripting attacks under certain circumstances.

https://snyk.io/test/npm/angular/1.5.8

Remediation recommendation: Upgrade Angular.js version to 1.6.9 or higher. We can upgrade to latest available 1.7.8 version

https://github.com/angular/angular.js/blob/master/CHANGELOG.md

Steps to Reproduce

None

Workaround

None

Activity

Show:
Duplicate

Details

Assignee

Reporter

Edit Screen Preamble

<div class="notify info" style="margin-bottom: 10px;">
If you are a Pentaho customer, please use the <a href="http://support.pentaho.com">Customer Support portal</a> to log issues.
<p />
This system is used for logging bugs and enhancement requests only. Please use our <a href="https://community.pentaho.com">community at https://community.pentaho.com</a> if you have questions, configuration issues, or have an issue with a marketplace plugin as Pentaho does not support marketplace plugins unless written by Pentaho.
<p />
Lastly, when creating a bug, please provide as much detail as possible. To prevent unnecessary delays in reviewing your issue, please attach complete server logs, SQL/MDX logs where applicable, schemas, etc. Also, screen-shots and screen-cams are especially helpful in demonstrating the issue.
<p />
Thank-you so much,<br />
The Pentaho Team
</div>

Notice

<div class="notify info" style="margin-bottom: 10px;">
When an issue is open, the "Fix Version/s" field conveys a target, not necessarily a commitment. When an issue is closed, the "Fix Version/s" field conveys the version that the issue was fixed in.
</div>

Sprint Team

Millennium Falcon

Story Points

Fix versions

Affects versions

Priority

Created May 22, 2019 at 10:20 AM
Updated March 3, 2023 at 6:45 PM
Resolved September 4, 2020 at 2:06 PM