CVE-2024-25677

In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.
Configurations

Configuration 1 (hide)

cpe:2.3:a:minbrowser:min:1.29.0:*:*:*:*:*:*:*

History

15 Feb 2024, 19:43

Type Values Removed Values Added
CPE cpe:2.3:a:minbrowser:min:1.29.0:*:*:*:*:*:*:*
References () https://github.com/minbrowser/min/security/advisories/GHSA-4w9v-7h8h-rv8x - () https://github.com/minbrowser/min/security/advisories/GHSA-4w9v-7h8h-rv8x - Third Party Advisory
First Time Minbrowser
Minbrowser min
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

09 Feb 2024, 14:26

Type Values Removed Values Added
Summary
  • (es) En Min anterior a 1.31.0, los archivos locales no se tratan correctamente como orígenes de seguridad únicos, lo que les permite solicitar incorrectamente recursos de orígenes cruzados. Por ejemplo, un archivo local puede solicitar otros archivos locales a través de un documento XML.

09 Feb 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-09 09:15

Updated : 2024-02-15 19:43


NVD link : CVE-2024-25677

Mitre link : CVE-2024-25677

CVE.ORG link : CVE-2024-25677


JSON object : View

Products Affected

minbrowser

  • min