Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.
History

Tue, 21 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 15:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 20 Jan 2025 16:00:00 +0000

Type Values Removed Values Added
Description Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6.
Title Vite allows any websites to send any requests to the development server and read the response
Weaknesses CWE-1385
CWE-346
CWE-350
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-01-21T14:52:53.680Z

Reserved: 2025-01-16T17:31:06.457Z

Link: CVE-2025-24010

cve-icon Vulnrichment

Updated: 2025-01-21T14:51:16.294Z

cve-icon NVD

Status : Received

Published: 2025-01-20T16:15:28.730

Modified: 2025-01-20T16:15:28.730

Link: CVE-2025-24010

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-01-20T15:53:30Z

Links: CVE-2025-24010 - Bugzilla