Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
References
Configurations
History
13 Sep 2022, 21:25
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:* |
|
References |
|
Information
Published : 2020-11-06 20:15
Updated : 2024-02-04 21:23
NVD link : CVE-2020-28168
Mitre link : CVE-2020-28168
CVE.ORG link : CVE-2020-28168
JSON object : View
Products Affected
axios
- axios
siemens
- sinec_ins
CWE
CWE-918
Server-Side Request Forgery (SSRF)