VDB

CISA-2024-39338

CISA-2024-39338 PUBLISHED CVSS 4 MEDIUM

Reported by mitre · Published August 9, 2024

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

Risk Scores

CVSS 3.1
4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected Products

VendorProductVersions
n/an/an/a
axiosaxios1.7.2, 1.7.2
n/an/a*, n/a

Timeline

  • Aug 9, 2024 CVE Published
  • Aug 15, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›