7.5
CVE-2024-29896
- EPSS 0.59%
- Veröffentlicht 28.03.2024 13:15:47
- Zuletzt bearbeitet 19.09.2025 15:59:51
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Astro-Shield's Content-Security-Policy header generation in middleware could be compromised by malicious injections
Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content is enabled and the web application serves content that can be partially controlled by external users, then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts. The fix is available in version 1.3.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kindspells ≫ Astro-shield Version1.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.59% | 0.436 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
https://github.com/KindSpells/astro-shield/commit/41b84576d37fa486a57005ea297658d0bc38566d
https://github.com/KindSpells/astro-shield/security/advisories/GHSA-w387-5qqw-7g8m