CVE-2019-14863: Angularjs

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Affected products

  • Angularjs Angularjs: from 1.0.0, up to and including 1.4.14
  • Red Hat Decision Manager: version 7.0 only
  • Red Hat Process Automation: version 7.0 only

Published 2020-01-02. Last modified 2026-06-17.