Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0.
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Hardened Images | RedHat | grafana13-1-main-13.1.6-0.6.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana12-4-main-12.4.12-0.3.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana13-2-main-13.2.1-0.9.hum1 | * |
| Node-axios | Ubuntu | upstream | * |