Description
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0488 | Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. |
Github GHSA |
GHSA-4w2v-q235-vp99 | Axios vulnerable to Server-Side Request Forgery |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:33:57.813Z
Reserved: 2020-11-02T00:00:00.000Z
Link: CVE-2020-28168
No data.
Status : Modified
Published: 2020-11-06T20:15:13.163
Modified: 2024-11-21T05:22:25.573
Link: CVE-2020-28168
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA