Security Advisory

CVE-2020-28168

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-11-06 19:22:38
Last updated 2024-08-04 16:33:57
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.