Vulnerabilities/

angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend

Severity:
High

Description

angular-server-side-configuration detects used environment variables in TypeScript (.ts) files during build time of an Angular CLI project. The detected environment variables are written to a ngssc.json file in the output directory. During deployment of an Angular based app, the environment variables based on the variables from ngssc.

Recommendation

Update the angular-server-side-configuration package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
angular-server-side-configuration
Anything's wrong? Let us know Last updated on March 24, 2023

This issue is available in SmartScanner Professional

See Pricing