Логотип exploitDog
bind:CVE-2024-29896
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-29896

Количество 2

Количество 2

nvd логотип

CVE-2024-29896

почти 2 года назад

Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content is enabled and the web application serves content that can be partially controlled by external users, then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts. The fix is available in version 1.3.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w387-5qqw-7g8m

почти 2 года назад

Content-Security-Policy header generation in middleware could be compromised by malicious injections

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-29896

Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content is enabled and the web application serves content that can be partially controlled by external users, then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts. The fix is available in version 1.3.0.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-w387-5qqw-7g8m

Content-Security-Policy header generation in middleware could be compromised by malicious injections

CVSS3: 7.5
1%
Низкий
почти 2 года назад

Уязвимостей на страницу