Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-28168

Опубликовано: 06 нояб. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 5.9

Описание

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

РелизСтатусПримечание
bionic

DNE

devel

needed

esm-apps/focal

needs-triage

esm-apps/jammy

needed

esm-apps/noble

needed

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needs-triage
groovy

ignored

end of life
hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
больше 5 лет назад

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

CVSS3: 5.9
nvd
больше 5 лет назад

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

CVSS3: 5.9
debian
больше 5 лет назад

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) ...

CVSS3: 5.9
github
около 5 лет назад

Axios vulnerable to Server-Side Request Forgery

CVSS3: 5.9
fstec
больше 4 лет назад

Уязвимость библиотеки axios прикладного программного обеспечения Аврора Центр, позволяющая нарушителю осуществить SSRF-атаку

4.3 Medium

CVSS2

5.9 Medium

CVSS3