vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Mon, 02 Dec 2024 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Intlify
Intlify vue-i18n
CPEs cpe:2.3:a:intlify:vue-i18n:*:*:*:*:*:*:*:*
Vendors & Products Intlify
Intlify vue-i18n
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 18:45:00 +0000

Type Values Removed Values Added
Description vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Cross-site Scripting vulnerability with prototype pollution in vue-i18n
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-29T18:32:36.527Z

Updated: 2024-12-02T22:24:19.591Z

Reserved: 2024-11-15T17:11:13.443Z

Link: CVE-2024-52809

cve-icon Vulnrichment

Updated: 2024-12-02T22:24:12.342Z

cve-icon NVD

Status : Received

Published: 2024-11-29T19:15:09.030

Modified: 2024-11-29T19:15:09.030

Link: CVE-2024-52809

cve-icon Redhat

No data.