This repository has been archived by the owner on Dec 9, 2023. It is now read-only.
CVE-2020-28168 (Medium) detected in axios-0.17.1.tgz #156
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2020-28168 - Medium Severity Vulnerability
Promise based HTTP client for the browser and node.js
Library home page: https://registry.npmjs.org/axios/-/axios-0.17.1.tgz
Path to dependency file: /Website/package.json
Path to vulnerable library: Website/node_modules/axios/package.json
Dependency Hierarchy:
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Publish Date: 2020-11-06
URL: CVE-2020-28168
Base Score Metrics:
Type: Upgrade version
Origin: axios/axios@c7329fe
Release Date: 2020-11-06
Fix Resolution: axios - 0.21.1
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: