First published: Fri Aug 09 2024(Updated: )
axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/axios | >=1.3.2<=1.7.3 | 1.7.4 |
Axios Axios | >=1.3.2<1.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.