Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollution flaw sets Object.prototype.headers, and trusted request interceptors return a new ordinary configuration without an own headers property. After the interceptor chain, dispatchRequest resolves the inherited headers during normalization. Downstream request processing can observe attacker-controlled headers, including authorization-related values. This issue is fixed in version 1.20.0.
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Hardened Images | RedHat | grafana13-1-main-13.1.6-0.6.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana12-4-main-12.4.12-0.3.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana13-2-main-13.2.1-0.9.hum1 | * |
| Node-axios | Ubuntu | upstream | * |