This is a migrated thread and some comments may be shown as answers.

AngularJS prior to 1.8.0 Vulnerable due to Security Issues

1 Answer 462 Views
General Discussions
This is a migrated thread and some comments may be shown as answers.
Alan
Top achievements
Rank 1
Alan asked on 09 Dec 2020, 11:56 AM

Hi

Our inclusion of the ~/Scripts/kendo/2017.2.504/angular.min.js file in our web application has been reported as a vulnerability by our customer as it is v1.4.6 and any version prior to v1.8.0 has security issues.

I read on the https://docs.telerik.com/kendo-ui/framework/AngularJS/angular-support page that, "Unlike their dependency on jQuery, the Kendo UI distributions can function correctly without AngularJS". Is it possible therefore to simply remove the angular.min.js file from our web application without any issue? Are there any dependencies on this file we would need to consider? The file has been included as part of the Telerik UI for ASP.NET MVC R2 2017 package in or web application.

Thanks for any help you can give.

Alan

1 Answer, 1 is accepted

Sort by
0
Petar
Telerik team
answered on 11 Dec 2020, 08:06 AM

Hi Alan,

I can see that the current ticket is submitted in the UI for ASP.NET MVC section of our forums. If you are NOT using any Angular JS functionality in your project, you can remove the angular.min.js and this removal should not affect the correct functionality of your application.

The Kendo UI for jQuery library has no dependency from angular.min.js.

Regards,
Petar
Progress Telerik

Virtual Classroom, the free self-paced technical training that gets you up to speed with Telerik and Kendo UI products quickly just got a fresh new look + new and improved content including a brand new Blazor course! Check it out at https://learn.telerik.com/.

Tags
General Discussions
Asked by
Alan
Top achievements
Rank 1
Answers by
Petar
Telerik team
Share this question
or