The following table lists the changes that have been made to the
CVE-2025-24010 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Jan. 20, 2025
Action Type Old Value New Value Added Description Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6. Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Added CWE CWE-346 Added CWE CWE-350 Added CWE CWE-1385 Added Reference https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6