Описание
solspace/craft-freeform Exposed to Known Axios Vulnerabilities via Precompiled Assets
Summary
The latest versions of both 4.x and 5.x are using Axios versions < 1.7.5 and as such are subject to known vulnerabilities as per: https://security.snyk.io/package/npm/axios
Details
We've had this flagged up in a pen test, which indicates the issue stems from this script: /freeform/plugin.js. I couldn't see any reference to vulnerable axios versions in your package.json files, but noticed some precompiled files in packages/plugin so I'm assuming those are where the issue lies.
Пакеты
Наименование
solspace/craft-freeform
composer
Затронутые версииВерсия исправления
< 4.1.22
4.1.22
Наименование
solspace/craft-freeform
composer
Затронутые версииВерсия исправления
>= 5.0.0-beta.1, < 5.5.9
5.5.9