Skip to content

[BUG] axios version lesser than 1.6.0 has Cross-Site Request Forgery vulnerability #719

@dutta-arnab1

Description

@dutta-arnab1

⚠️ Important Notice

Please differentiate the bug


🐛 Bug Report:

Describe the bug

axios version lesser than 1.6.0 has Cross-Site Request Forgery vulnerability. This package currently has dependency on @nestjs/axios v0.1.0 which references axios v0.27.0.

Steps to Reproduce

Check axios vulnerability.
GHSA-wf5p-g6vw-rhxx

Expected behavior

The vulnerability should be resolved by upgrading axios to version >1.6.0.

Screenshots

Operation System (please complete the following information):

  • OS: Windows
  • Version 10

Package System (please complete the following information):

  • Version 2.7.0 (latest)

Additional context

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions