First published: Wed Nov 08 2023(Updated: )
An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/axios | >=0.8.1<0.28.0 | 0.28.0 |
npm/axios | >=1.0.0<1.6.0 | 1.6.0 |
IBM IBM® Db2® on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | <=v3.5 through refresh 10v4.0 through refresh 9v4.5 through refresh 3v4.6 through refresh 6v4.7 through refresh 4v4.8 through refresh 4 | |
Axios Axios | =1.5.1 | |
redhat/axios | <1.6.0 | 1.6.0 |
=1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-45857.
The severity of CVE-2023-45857 has not been specified.
Axios 0.8.1 through 1.5.1 inadvertently includes the XSRF-TOKEN stored in cookies in the HTTP header X-XSRF-TOKEN for every request.
Axios versions 0.8.1 through 1.5.1 are affected by CVE-2023-45857.
To fix CVE-2023-45857, update to Axios 1.6.0 or later.