Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content

Announcements
Qlik Connect 2026 Agenda Now Available: Explore Sessions
cancel
Showing results for 
Search instead for 
Did you mean: 
sdcentre
Contributor II
Contributor II

AngularJS 1.8.3 security vulnerability

Hello Qlikers,

We in company use Qlik Analytics Platform (QAP), which is same Qlik Sense Enterprise with some limited and some added functionality, for external reporting on DMZ server via mashup/web page, so security is very strictly monitored.

In penetration test it was identified that Qlik Sense have bundled AngularJS 1.8.3 version, which is now out of official support and security vulnerabilities for this version of AngularJS are known (CVE-2022-25844 and CVE-2022-25869). Here's a link: https://security.snyk.io/package/npm/angular/1.8.3

Qlik announced some time ago, that it will continue to support AngularJS, and will be responsible for bugfixes and improvements: https://community.qlik.com/t5/Official-Support-Articles/Qlik-will-continue-the-support-for-AngularJS...

At the current moment, because of this reason, our platform is not as secured as it could be, unfortunately.

Does anyone of you knows - are these issues fixed for AngularJS included in the Qlik Sense installation, if not, is Qlik planning to fix this in next patches/releases?

And if not - is there any fix/workaround to mitigate security vulnerabilities, have you some experience with same topic?

Best regards

Labels (2)
0 Replies