Логотип exploitDog
bind:CVE-2025-24010
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-24010

Количество 5

Количество 5

redhat логотип

CVE-2025-24010

8 месяцев назад

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-24010

8 месяцев назад

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-24010

8 месяцев назад

Vite is a frontend tooling framework for javascript. Vite allowed any ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vg6x-rcgg-rjx6

8 месяцев назад

Websites were able to send any requests to the development server and read the response in vite

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-01641

8 месяцев назад

Уязвимость механизма CORS локального сервера разработки приложений Vite, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-24010

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-24010

Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-24010

Vite is a frontend tooling framework for javascript. Vite allowed any ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-vg6x-rcgg-rjx6

Websites were able to send any requests to the development server and read the response in vite

CVSS3: 6.5
0%
Низкий
8 месяцев назад
fstec логотип
BDU:2025-01641

Уязвимость механизма CORS локального сервера разработки приложений Vite, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
0%
Низкий
8 месяцев назад

Уязвимостей на страницу