Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-57965

Опубликовано: 29 янв. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*
Версия до 1.7.8 (исключая)

EPSS

Процентиль: 35%
0.00142
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-346

Связанные уязвимости

ubuntu
около 1 года назад

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

debian
около 1 года назад

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a U ...

github
около 1 года назад

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.

EPSS

Процентиль: 35%
0.00142
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-346