Количество 5
Количество 5

CVE-2025-24010
Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.

CVE-2025-24010
Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.
CVE-2025-24010
Vite is a frontend tooling framework for javascript. Vite allowed any ...
GHSA-vg6x-rcgg-rjx6
Websites were able to send any requests to the development server and read the response in vite

BDU:2025-01641
Уязвимость механизма CORS локального сервера разработки приложений Vite, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2025-24010 Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад |
![]() | CVE-2025-24010 Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад |
CVE-2025-24010 Vite is a frontend tooling framework for javascript. Vite allowed any ... | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
GHSA-vg6x-rcgg-rjx6 Websites were able to send any requests to the development server and read the response in vite | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
![]() | BDU:2025-01641 Уязвимость механизма CORS локального сервера разработки приложений Vite, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу