漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
axios before 1.18.0 Prototype Pollution via auth subfields
Vulnerability Description
axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primitive and makes an axios request with an own auth object that omits the username and/or password properties, axios reads the inherited Object.prototype.username and Object.prototype.password values and uses them to construct an outbound 'Authorization: Basic ...' header. axios itself does not pollute prototypes. The practical impact is outbound request tampering: an attacker who controls the polluted prototype values can inject attacker-chosen Basic auth credentials or replace an existing Authorization header. Credential disclosure is only possible under additional application-specific conditions.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Vulnerability Type
CWE-1321
Vulnerability Title
Axios 输入验证错误漏洞
Vulnerability Description
Axios是Axios团队开源的一款基于Promise(异步编程的一种解决方案)的HTTP客户端。 Axios 1.15.2版本至1.18.0之前版本存在输入验证错误漏洞,该漏洞源于Basic auth子字段处理存在原型污染读取端小工具,axios会从继承的Object.prototype中读取username和password值,可能导致攻击者篡改外发请求,注入自定义Basic auth凭据或替换现有Authorization头。
CVSS Information
N/A
Vulnerability Type
N/A