Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-27152

Опубликовано: 07 мар. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.

A flaw was discovered in Axios. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, which can potentially lead to server-side request forgery (SSRF). This issue impacts both server-side and client-side usage of axios.

Отчет

As per further reports credential leakage is not possible in this SSRF, which is why confidentiality has been marked as low and Red Hat has evaluated this vulnerability as moderate severity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3io.cryostat-cryostat3Fix deferred
Migration Toolkit for Applications 7mta/mta-cli-rhel9Fix deferred
Migration Toolkit for Applications 7mta/mta-ui-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/multicluster-engine-console-mce-rhel8Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-api-rhel8Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-db-migration-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2350618axios: Possible SSRF and Credential Leakage via Absolute URL in axios Requests

EPSS

Процентиль: 22%
0.00072
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 года назад

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.

CVSS3: 5.3
nvd
около 1 года назад

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.

msrc
7 месяцев назад

Possible SSRF and Credential Leakage via Absolute URL in axios Requests

CVSS3: 5.3
debian
около 1 года назад

axios is a promise based HTTP client for the browser and node.js. The ...

suse-cvrf
12 месяцев назад

Security update for pgadmin4

EPSS

Процентиль: 22%
0.00072
Низкий

5.3 Medium

CVSS3