Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53865 | In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability. |
Fri, 19 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axios
Axios axios |
|
| CPEs | cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Axios
Axios axios |
Wed, 29 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jan 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-346 | |
| Metrics |
cvssV3_1
|
Wed, 29 Jan 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-29T14:14:23.882Z
Reserved: 2025-01-29T00:00:00.000Z
Link: CVE-2024-57965
Updated: 2025-01-29T14:14:20.293Z
Status : Analyzed
Published: 2025-01-29T09:15:08.183
Modified: 2025-09-19T19:38:55.067
Link: CVE-2024-57965
No data.
OpenCVE Enrichment
No data.
EUVD