QID 982965
QID 982965: Nodejs (npm) Security Update for axios (GHSA-4w2v-q235-vp99)
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4w2v-q235-vp99 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4w2v-q235-vp99 -
github.com/advisories/GHSA-4w2v-q235-vp99
CVEs related to QID 982965
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4w2v-q235-vp99 | axios |
|