VDB
CVE-2024-11023
CVE-2024-11023
PUBLISHED
CVSS 5.199999809265137 MEDIUM
Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server
EPSS 0.13% · 2.6th percentile
Risk Scores
CVSS 4.0
5.199999809265137
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H
EPSS Score
0.13%
2.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| npm | firebase | 0 |
| firebase_javascript_sdk | 0 | |
| Firebase | JavaScript SDK | 0 |
Timeline
- Jan 20, 1970 Fix PR Merged
- Nov 18, 2024 CVE Published
- Nov 18, 2024 Coalition ESS Score
- Nov 18, 2024 Coalition ESS Score
- Nov 18, 2024 PoC Published
- Nov 19, 2024 EPSS Score
- Dec 8, 2024 EPSS Score
- Dec 25, 2024 EPSS Score
- Jan 12, 2025 EPSS Score
- Jan 29, 2025 EPSS Score
- Feb 16, 2025 EPSS Score
- Mar 6, 2025 EPSS Score
References
- https://github.com/firebase/firebase-js-sdk/pull/8056 fix
- https://firebase.google.com/support/release-notes/js#version_1090_-_march_14_2024 url
- https://nvd.nist.gov/vuln/detail/CVE-2024-11023 advisory
- https://github.com/firebase/firebase-js-sdk package
- https://github.com/firebase/firebase-js-sdk/commit/245dd26e19b6c16aca7e1b7e597ed5784c2984ba fix