Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-57965

Опубликовано: 29 янв. 2025
Источник: debian
EPSS Низкий

Описание

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-axiosfixed1.7.9+dfsg-1package
node-axiosfixed1.2.1+dfsg-1+deb12u1bookwormpackage
node-axiospostponedbullseyepackage

Примечания

  • https://github.com/axios/axios/issues/6351

  • https://github.com/axios/axios/commit/0a8d6e19da5b9899a2abafaaa06a75ee548597db (v1.7.8)

  • https://github.com/axios/axios/pull/6714

EPSS

Процентиль: 31%
0.00118
Низкий

Связанные уязвимости

ubuntu
около 1 года назад

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

nvd
около 1 года назад

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

github
около 1 года назад

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

EPSS

Процентиль: 31%
0.00118
Низкий