Skip to content

axios vuln - CVE-2020-28168 #721

@brendan-miller-snyk

Description

@brendan-miller-snyk

Description

bolt-js is currently utilising axios v0.19.0 which is affected by CVE-2020-28168 (SNYK-JS-AXIOS-1038255) which is present in all versions of axios prior to v0.21.1.

Vuln was fixed in v0.21.1 - axios/axios#3410

What type of issue is this? (place an x in one of the [ ])

  • bug
  • enhancement (feature request)
  • question
  • documentation related
  • example code related
  • testing related
  • discussion

Requirements (place an x in each of the [ ])

  • I've read and understood the Contributing guidelines and have done my best effort to follow them.
  • I've read and agree to the Code of Conduct.
  • I've searched for any related issues and avoided creating a duplicate issue.

Bug Report

Filling out the following details about bugs will help us solve your issue sooner.

Reproducible in:

package version: 2.5.0

node version: 15.0.1

OS version(s): MacOS 11.1

Steps to reproduce:

  1. Scanned via Snyk: https://app.snyk.io/test/npm/@slack/bolt/2.5.0

Expected result:

N/A

Actual result:

N/A

Attachments:

CVE Entry: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28168
Snyk Vuln DB: https://app.snyk.io/vuln/SNYK-JS-AXIOS-1038255

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions