VulnerabilityAnalyzed
CVE-2024-57965
NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.
CRITICAL 9.8EPSS 0.38%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-346
- Affected
- axios/axios
- Source
- cve@mitre.org
References
- https://github.com/axios/axios/commit/0a8d6e19da5b9899a2abafaaa06a75ee548597dbPatch
- https://github.com/axios/axios/issues/6351Issue Tracking
- https://github.com/axios/axios/pull/6714Issue Tracking, Patch
- https://github.com/axios/axios/releases/tag/v1.7.8Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.