Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fh7x-2848-jmpf

Опубликовано: 29 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 0

Описание

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

EPSS

Процентиль: 35%
0.00142
Низкий

0 Low

CVSS3

Дефекты

CWE-346

Связанные уязвимости

ubuntu
около 1 года назад

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

nvd
около 1 года назад

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

debian
около 1 года назад

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a U ...

EPSS

Процентиль: 35%
0.00142
Низкий

0 Low

CVSS3

Дефекты

CWE-346