CVE-2024-29896
Last modified
CVE-2024-29896 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content is enabled and the web application serves content that can be partially controlled by external users, then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content is enabled and the web application serves content that can be partially controlled by external users, then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts. The fix is available in version 1.3.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kindspells | Astro-Shield | 1.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-29896?
How severe is CVE-2024-29896?
How do I fix CVE-2024-29896?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-29890DataLens is a business intelligence and data visualization s…8.8
- CVE-2024-29891ZITADEL users can upload their own avatar image and various …8.7
- CVE-2024-29892ZITADEL, open source authentication management software, use…4.9
- CVE-2024-29893Argo CD is a declarative, GitOps continuous delivery tool fo…6.5
- CVE-2024-29894Cacti provides an operational monitoring and fault managemen…4.7
- CVE-2024-29895Cacti provides an operational monitoring and fault managemen…10
- CVE-2024-29897CreateWiki is Miraheze's MediaWiki extension for requesting …4.9
- CVE-2024-29898CreateWiki is Miraheze's MediaWiki extension for requesting …6.5
- CVE-2024-2990A vulnerability, which was classified as critical, was found…8.8
- CVE-2024-29900Electron Packager bundles Electron-based application source …7.5
- CVE-2024-29901The AuthKit library for Next.js provides helpers for authent…8.1
- CVE-2024-29902Cosign provides code signing and transparency for containers…5.9
Are you affected by CVE-2024-29896?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
