First published: Wed Nov 08 2023(Updated: )
An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
npm/axios | >=0.8.1<0.28.0 | 0.28.0 |
npm/axios | >=1.0.0<1.6.0 | 1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is GHSA-wf5p-g6vw-rhxx.
The severity of GHSA-wf5p-g6vw-rhxx is high.
The versions 0.8.1 through 1.5.1 of Axios are affected by GHSA-wf5p-g6vw-rhxx.
Attackers can exploit GHSA-wf5p-g6vw-rhxx by viewing sensitive information stored in the XSRF-TOKEN cookies.
You can fix GHSA-wf5p-g6vw-rhxx by updating Axios to version 1.6.0 or higher.