Описание
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
node-axios | fixed | 1.6.2+dfsg-1 | package | |
node-axios | fixed | 1.2.1+dfsg-1+deb12u1 | bookworm | package |
node-axios | no-dsa | bullseye | package | |
node-axios | no-dsa | buster | package |
Примечания
https://github.com/axios/axios/issues/6006
https://github.com/axios/axios/commit/96ee232bd3ee4de2e657333d4d2191cd389e14d0 (v1.6.0)
EPSS
Связанные уязвимости
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Axios Cross-Site Request Forgery Vulnerability
Уязвимость библиотеки axios, связанная с подделкой межсайтовых запросов, позволяющая нарушителю получить несанкционированный доступ к токену XSRF-TOKEN
EPSS