CVE-2024-30250
Last modified
CVE-2024-30250 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques. Versions from 1.2.0 to 1.3.1 of Astro-Shield allow bypass to the allow-lists for cross-origin resources by introducing valid `integrity` attributes to the injected code. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques. Versions from 1.2.0 to 1.3.1 of Astro-Shield allow bypass to the allow-lists for cross-origin resources by introducing valid `integrity` attributes to the injected code. This implies that the injected SRI hash would be added to the generated CSP header, which would lead the browser to believe that the injected resource is legit. This vulnerability is patched in version 1.3.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kindspells | Astro-Shield | >= 1.2.0, < 1.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-30250?
How severe is CVE-2024-30250?
How do I fix CVE-2024-30250?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-30245Improper Neutralization of Special Elements used in an SQL C…7.6
- CVE-2024-30246Tuleap is an Open Source Suite to improve management of soft…7.1
- CVE-2024-30247NextcloudPi is a ready to use image for Virtual Machines, Ra…9.8
- CVE-2024-30248Piccolo Admin is an admin interface/content management syste…7.7
- CVE-2024-30249Cloudburst Network provides network components used within C…8.6
- CVE-2024-3025mintplex-labs/anything-llm is vulnerable to path traversal a…9.9
- CVE-2024-30251aiohttp is an asynchronous HTTP client/server framework for …7.5
- CVE-2024-30252Livemarks is a browser extension that provides RSS feed book…2.6
- CVE-2024-30253@solana/web3.js is the Solana JavaScript SDK. Using particul…7.5
- CVE-2024-30254MesonLSP is an unofficial, unendorsed language server for me…5.8
- CVE-2024-30255Envoy is a cloud-native, open source edge and service proxy.…7.5
- CVE-2024-30256Open WebUI is a user-friendly WebUI for LLMs. Open-webui is …6.4
Are you affected by CVE-2024-30250?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
