CVE-2024-57965

CVSS 3.1 Score 0 of 10 (low)

Details

Published Jan 29, 2025
CWE ID 346

Summary

CVE-2024-57965 is a vulnerability affecting axios before version 1.7.8. The issue lies in the lib/helpers/isURLSameOrigin.js file, where a URL object is not used to determine the origin, and there is an unwanted setAttribute('href',href) call. This could potentially lead to security concerns, although some experts argue that the fix only addresses a warning message from a Static Application Security Testing (SAST) tool and does not actually resolve the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share