Skip to content

Address another potential security vulnerability w/ axios#19

Merged
gurbirkalsi merged 1 commit intomasterfrom
portante-patch-2
May 6, 2021
Merged

Address another potential security vulnerability w/ axios#19
gurbirkalsi merged 1 commit intomasterfrom
portante-patch-2

Conversation

@portante
Copy link
Copy Markdown
Member

@portante portante commented May 6, 2021

See GHSA-4w2v-q235-vp99 ...

Vulnerable versions: < 0.21.1
Patched version: 0.21.1

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

See also PR #18.

See GHSA-4w2v-q235-vp99 ...

Vulnerable versions: < 0.21.1
Patched version: 0.21.1

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

See also PR #18.
@portante portante requested a review from gurbirkalsi May 6, 2021 13:40
@gurbirkalsi gurbirkalsi merged commit 3de5403 into master May 6, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants