Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8hc4-vh64-cxmj | Server-Side Request Forgery in axios |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat discovery
|
|
| CPEs | cpe:/o:redhat:discovery:1.0::el9 | |
| Vendors & Products |
Redhat discovery
|
Wed, 13 Nov 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift
|
|
| CPEs | cpe:/a:redhat:openshift:4.17::el9 | |
| Vendors & Products |
Redhat openshift
|
Tue, 22 Oct 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat network Observ Optr
|
|
| CPEs | cpe:/a:redhat:network_observ_optr:1.7.0::el9 | |
| Vendors & Products |
Redhat network Observ Optr
|
Tue, 15 Oct 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Serverless
|
|
| CPEs | cpe:/a:redhat:openshift_serverless:1.34::el8 | |
| Vendors & Products |
Redhat openshift Serverless
|
Thu, 26 Sep 2024 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhmt
|
|
| CPEs | cpe:/a:redhat:rhmt:1.8::el8 | |
| Vendors & Products |
Redhat rhmt
|
Sat, 14 Sep 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Devspaces
|
|
| CPEs | cpe:/a:redhat:openshift_devspaces:3::el8 | |
| Vendors & Products |
Redhat openshift Devspaces
|
Fri, 06 Sep 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat service Mesh |
|
| CPEs | cpe:/a:redhat:service_mesh:2.4::el8 cpe:/a:redhat:service_mesh:2.5::el8 cpe:/a:redhat:service_mesh:2.6::el8 cpe:/a:redhat:service_mesh:2.6::el9 |
|
| Vendors & Products |
Redhat
Redhat service Mesh |
Fri, 16 Aug 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | axios: axios: Server-Side Request Forgery | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 15 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 12 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axios
Axios axios |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Axios
Axios axios |
|
| Metrics |
cvssV3_1
|
Fri, 09 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-15T19:26:34.904Z
Reserved: 2024-06-23T00:00:00.000Z
Link: CVE-2024-39338
Updated: 2024-08-12T20:17:16.043Z
Status : Analyzed
Published: 2024-08-12T13:38:24.487
Modified: 2024-08-23T18:35:36.313
Link: CVE-2024-39338
OpenCVE Enrichment
No data.
Github GHSA