CVE-2025-24010
CVE-2025-24010
Título es
CVE-2025-24010
Lun, 20/01/2025 – 16:15
Tipo
CWE-346
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-24010
Descripción en
Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.
20/01/2025
20/01/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
6.50
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Enviar en el boletín
Off
