You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Feb 18, 2022. It is now read-only.
Affected package: axios
Ecosystem: NPM
Affected version range: < 0.21.1
Summary: Server-Side Request Forgery in Axios
Description: Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
identifiers: [{'type': 'GHSA', 'value': 'GHSA-4w2v-q235-vp99'}, {'type': 'CVE', 'value': 'CVE-2020-28168'}]
Fixed Version: 0.21.1
Created Date = January 25, 2022
---
Affected package: axios
Ecosystem: NPM
Affected version range: <= 0.21.1
Summary: Incorrect Comparison in axios
Description: axios is vulnerable to Inefficient Regular Expression Complexity
identifiers: [{'type': 'GHSA', 'value': 'GHSA-cph5-m8f7-6c5x'}, {'type': 'CVE', 'value': 'CVE-2021-3749'}]
Fixed Version: 0.21.2
Created Date = January 25, 2022
---
The text was updated successfully, but these errors were encountered:
The text was updated successfully, but these errors were encountered: