logo

Vulnerability details for CVE-2020-28168 

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

CVSS Score (Vector) 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N)
ThreatWorx Rating 3 - Severe
Weakness Types Server-Side Request Forgery (SSRF), Access Bypass, CVE-2020-7793 , Memory Overflow, Code Execution
Reported By Ubuntu, GitHub, Red Hat, Open Source, CISA ICS, Security Research, IoT
First Reported Oct 29, 2020 by GitHub
Last Updated Oct 17, 2024 by Security Research
NVD Status Published CVE-2020-28168
Affected Products 25 affected product(s) reported by NVD, GitHub, Red Hat, Open Source, CISA ICS, Security Research, IoT
Patches 9 patch(es) published by Ubuntu, IoT
Remediations 5 remediation(s) published by GitHub, Open Source, CISA ICS
Latest Reference Security Research