Логотип exploitDog
bind:CVE-2025-69202
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-69202

Количество 2

Количество 2

nvd логотип

CVE-2025-69202

около 1 месяца назад

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth tokens, axios-cache-interceptor returns incorrect cached responses, leading to authorization bypass. The cache key is generated only from the URL, ignoring request headers like `Authorization`. When the server responds with `Vary: Authorization` (indicating the response varies by auth token), the library ignores this, causing all requests to share the same cache regardless of authorization. Server-side applications (APIs, proxies, backend services) that use axios-cache-interceptor to cache requests to upstream services, handle requests from multiple users with different auth tokens, and upstream services replies on `Vary` to differentiate caches are affected. Browser/client-side applications (single user per browser session) are not affected. Services using different auth tokens to call upstream services will return incorrect cached data, bypas

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-x4m5-4cw8-vc44

около 1 месяца назад

axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-69202

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth tokens, axios-cache-interceptor returns incorrect cached responses, leading to authorization bypass. The cache key is generated only from the URL, ignoring request headers like `Authorization`. When the server responds with `Vary: Authorization` (indicating the response varies by auth token), the library ignores this, causing all requests to share the same cache regardless of authorization. Server-side applications (APIs, proxies, backend services) that use axios-cache-interceptor to cache requests to upstream services, handle requests from multiple users with different auth tokens, and upstream services replies on `Vary` to differentiate caches are affected. Browser/client-side applications (single user per browser session) are not affected. Services using different auth tokens to call upstream services will return incorrect cached data, bypas

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-x4m5-4cw8-vc44

axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу