---
title: "CVE-2022-25844"
canonical: "https://kb.cynergy.app/space/MD/923729984/CVE-2022-25844"
format: markdown
---
**Description**

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.

**Published On**

05/01/2022

**Updated On**

10/28/2022

**Trending**

FALSE

**CWE**

[<u>CWE-770</u>](http://cwe.mitre.org/data/definitions/770.html)

**Exploit**

[https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2772738](https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2772738) 

 

**Mitigation:**

![image](media://607aafeb-2580-48d4-b8e9-e4b5c4e3a7c9)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

**<span style="color: #97a0af">Note: </span>**<span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Angular JS has reached End of Life, it is suggested to move to alternative frameworks

- [https://angularjs.org/](https://angularjs.org/)