First published: Fri Nov 06 2020(Updated: )
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Pak for Automation | <=20.0.3 | |
IBM Cloud Pak for Automation | <=20.0.2 IF002 | |
Axios Axios | >=0.19.0<=0.21.0 | |
Siemens Sinec Ins | <1.0 | |
Siemens Sinec Ins | =1.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28168 is a Server-Side Request Forgery (SSRF) vulnerability in the axios NPM package version 0.21.0.
The vulnerability is caused by improper input validation in the axios module of Node.js, allowing an attacker to conduct an SSRF attack by providing a URL that redirects to a restricted host or IP address.
The severity of CVE-2020-28168 is medium with a CVSS score of 5.9.
IBM Cloud Pak for Automation versions up to 20.0.3, IBM Cloud Pak for Automation versions up to 20.0.2 IF002, and Siemens Sinec Ins version 1.0-sp1 are affected by CVE-2020-28168.
Update the affected software packages to a version that includes a fix for the vulnerability.