An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Axios | Axios | 1.5.1 (including) | 1.5.1 (including) |
Migration Toolkit for Runtimes 1 on RHEL 8 | RedHat | axios | * |
MTA-6.2-RHEL-9 | RedHat | mta/mta-windup-addon-rhel9:6.2.3-2 | * |
MTA-7.0-RHEL-9 | RedHat | mta/mta-cli-rhel9:7.0.3-16 | * |
MTA-7.0-RHEL-9 | RedHat | mta/mta-ui-rhel9:7.0.3-13 | * |
Red Hat Ansible Automation Platform 2.4 for RHEL 8 | RedHat | automation-controller-0:4.5.5-2.el8ap | * |
Red Hat Ansible Automation Platform 2.4 for RHEL 9 | RedHat | automation-controller-0:4.5.5-2.el9ap | * |
Red Hat Migration Toolkit for Containers 1.8 | RedHat | rhmtc/openshift-migration-ui-rhel8:v1.8.3-4 | * |
RHEL-8-CNV-4.12 | RedHat | container-native-virtualization/kubevirt-console-plugin:v4.12.12-7 | * |
RHEL-9-CNV-4.13 | RedHat | container-native-virtualization/kubevirt-console-plugin-rhel9:v4.13.10-387 | * |
RHEL-9-CNV-4.14 | RedHat | container-native-virtualization/kubevirt-console-plugin-rhel9:v4.14.6-195 | * |
RHEL-9-CNV-4.15 | RedHat | container-native-virtualization/kubevirt-console-plugin-rhel9:v4.15.2-383 | * |
RHEL-9-CNV-4.16 | RedHat | container-native-virtualization/kubevirt-console-plugin-rhel9:v4.16.0-4001 | * |
Node-axios | Ubuntu | bionic | * |
Node-axios | Ubuntu | lunar | * |
Node-axios | Ubuntu | mantic | * |
Node-axios | Ubuntu | trusty | * |
Node-axios | Ubuntu | xenial | * |