-
-
Notifications
You must be signed in to change notification settings - Fork 11.6k
Possible bug: Vulnerability SSRF #3407
Copy link
Copy link
Closed
Milestone
Description
Describe the bug
In my current project we are using Snyk to catch any possible issues and vulnerabilities.
Snyk reports that since version 0.19.0 there is SSRF vulnerability that has no been fixed yet.
This is the message:
Affected versions of this package are vulnerable to Server-Side Request Forgery (SSRF). An attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Could you please verify?
Thanks in advance.
To Reproduce
Any pen tests or just using Snyk to scan any app that uses axios.
Expected behavior
No vulnerabilities alerts.
Environment
- Axios Version [0.21.0]
- Adapter [HTTP]
- Browser [All]
- Browser Version [x]
- Node.js Version [12.14.1]
- OS: [x]
- Additional Library Versions [x]
Additional context/Screenshots
Add any other context about the problem here. If applicable, add screenshots to help explain.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels