Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-39338

Disclosure Date: August 12, 2024 (last updated August 24, 2024)
axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.
Attacker Value
Unknown

CVE-2023-45857

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Attacker Value
Unknown

CVE-2021-3749

Disclosure Date: August 31, 2021 (last updated November 08, 2023)
axios is vulnerable to Inefficient Regular Expression Complexity
Attacker Value
Unknown

CVE-2020-28168

Disclosure Date: November 06, 2020 (last updated November 08, 2023)
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Attacker Value
Unknown

CVE-2019-10742

Disclosure Date: May 07, 2019 (last updated November 27, 2024)
Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.
0