CVE-2020-28168: SSRF
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Other sources
Node.js axios module is vulnerable to server-side request forgery, caused by improper input validation. By providing a URL that responds with a redirect to a restricted host or IP address, an attacker could exploit this vulnerability to conduct SSRF attack to bypass a proxy.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-28168?
CVE-2020-28168 is a Server-Side Request Forgery (SSRF) vulnerability in the axios NPM package version 0.21.0.
How does the CVE-2020-28168 vulnerability occur?
The vulnerability is caused by improper input validation in the axios module of Node.js, allowing an attacker to conduct an SSRF attack by providing a URL that redirects to a restricted host or IP address.
What is the severity of CVE-2020-28168?
The severity of CVE-2020-28168 is medium with a CVSS score of 5.9.
Which software products are affected by CVE-2020-28168?
IBM Cloud Pak for Automation versions up to 20.0.3, IBM Cloud Pak for Automation versions up to 20.0.2 IF002, and Siemens Sinec Ins version 1.0-sp1 are affected by CVE-2020-28168.
How can the CVE-2020-28168 vulnerability be fixed?
Update the affected software packages to a version that includes a fix for the vulnerability.