CVE-2023-45857

Axios Cross-Site Request Forgery Vulnerability in npm/axios

Identifiers

CVE-2023-45857, GHSA-wf5p-g6vw-rhxx

Package Slug

npm/axios

Vulnerability

Axios Cross-Site Request Forgery Vulnerability

Description

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

Affected Versions

All versions starting from 0.8.1 before 1.6.0

Solution

Upgrade to version 1.6.0 or above.

Last Modified

2023-11-10

source