Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

redhat логотип

CVE-2025-24010

больше 1 года назад

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-24010

больше 1 года назад

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-24010

больше 1 года назад

Vite is a frontend tooling framework for javascript. Vite allowed any ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vg6x-rcgg-rjx6

больше 1 года назад

Websites were able to send any requests to the development server and read the response in vite

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-01641

больше 1 года назад

Уязвимость механизма CORS локального сервера разработки приложений Vite, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-24010

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-24010

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-24010

Vite is a frontend tooling framework for javascript. Vite allowed any ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-vg6x-rcgg-rjx6

Websites were able to send any requests to the development server and read the response in vite

CVSS3: 6.5
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-01641

Уязвимость механизма CORS локального сервера разработки приложений Vite, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу