What happened?
Description
axios versions before 1.6.8 depends on follow-redirects before 1.15.6, which could leak the proxy authentication credentials
axios/axios#6300
CVE-2024-39338: Server-Side Request Forgery in axios
Steps to reproduce
- Navigate to the following URL: https://example.com/admin/login
- Open the browser's built in developer tools
- Enter the following string into the JavaScript console: axios.VERSION
- Note that the application includes a version of axios 1.6.5 which has known security issues associated with it
Craft CMS version
5.4.9
PHP version
No response
Operating system and version
No response
Database type and version
No response
Image driver and version
No response
Installed plugins and versions
What happened?
Description
axios versions before 1.6.8 depends on follow-redirects before 1.15.6, which could leak the proxy authentication credentials
axios/axios#6300
CVE-2024-39338: Server-Side Request Forgery in axios
Steps to reproduce
Craft CMS version
5.4.9
PHP version
No response
Operating system and version
No response
Database type and version
No response
Image driver and version
No response
Installed plugins and versions