First published: Fri Aug 09 2024(Updated: )
axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/axios | >=1.3.2<=1.7.3 | 1.7.4 |
Axios | >=1.3.2<1.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39338 is classified as a medium severity vulnerability due to its potential for server-side request forgery.
To fix CVE-2024-39338, upgrade axios to version 1.7.4 or later.
Versions of axios from 1.3.2 to 1.7.3 are affected by CVE-2024-39338.
The impact of CVE-2024-39338 includes the possible exposure of internal systems due to SSRF vulnerabilities.
Yes, IBM Analytics Content Hub versions up to and including 2.0 are affected by CVE-2024-39338.