Skip to content

Possible bug: Vulnerability SSRF #3407

@parichkova

Description

@parichkova

Describe the bug

In my current project we are using Snyk to catch any possible issues and vulnerabilities.
Snyk reports that since version 0.19.0 there is SSRF vulnerability that has no been fixed yet.

This is the message:
Affected versions of this package are vulnerable to Server-Side Request Forgery (SSRF). An attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

Could you please verify?
Thanks in advance.

To Reproduce

Any pen tests or just using Snyk to scan any app that uses axios.

Expected behavior

No vulnerabilities alerts.

Environment

  • Axios Version [0.21.0]
  • Adapter [HTTP]
  • Browser [All]
  • Browser Version [x]
  • Node.js Version [12.14.1]
  • OS: [x]
  • Additional Library Versions [x]

Additional context/Screenshots

Add any other context about the problem here. If applicable, add screenshots to help explain.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions