Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-28168

Опубликовано: 06 нояб. 2020
Источник: debian
EPSS Низкий

Описание

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-axiosfixed0.21.1+dfsg-1package
node-axiosno-dsabusterpackage

Примечания

  • https://github.com/axios/axios/issues/3369

EPSS

Процентиль: 63%
0.00446
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 5 лет назад

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

CVSS3: 5.9
redhat
больше 5 лет назад

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

CVSS3: 5.9
nvd
больше 5 лет назад

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

CVSS3: 5.9
github
около 5 лет назад

Axios vulnerable to Server-Side Request Forgery

CVSS3: 5.9
fstec
больше 4 лет назад

Уязвимость библиотеки axios прикладного программного обеспечения Аврора Центр, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 63%
0.00446
Низкий