Описание
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| node-axios | fixed | 1.15.0-1 | package | |
| node-axios | no-dsa | trixie | package | |
| node-axios | no-dsa | bookworm | package | |
| node-axios | postponed | bullseye | package |
Примечания
https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx
https://github.com/axios/axios/pull/10660
Fixed by: https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1 (v1.15.0)
EPSS
Связанные уязвимости
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
EPSS