Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-45857

Опубликовано: 08 нояб. 2023
Источник: debian
EPSS Низкий

Описание

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-axiosfixed1.6.2+dfsg-1package
node-axiosfixed1.2.1+dfsg-1+deb12u1bookwormpackage
node-axiosno-dsabullseyepackage
node-axiosno-dsabusterpackage

Примечания

  • https://github.com/axios/axios/issues/6006

  • https://github.com/axios/axios/commit/96ee232bd3ee4de2e657333d4d2191cd389e14d0 (v1.6.0)

EPSS

Процентиль: 31%
0.00113
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

CVSS3: 6.5
redhat
больше 1 года назад

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

CVSS3: 6.5
nvd
больше 1 года назад

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

CVSS3: 6.5
github
больше 1 года назад

Axios Cross-Site Request Forgery Vulnerability

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость библиотеки axios, связанная с подделкой межсайтовых запросов, позволяющая нарушителю получить несанкционированный доступ к токену XSRF-TOKEN

EPSS

Процентиль: 31%
0.00113
Низкий