漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
axios before 1.18.0 Prototype Pollution via bodyless methods
Vulnerability Description
axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before config normalization, causing an attacker-controlled body to be sent on requests that did not set one. Additional low-level paths, only reachable when calling exported adapters/helpers (e.g. lib/adapters/http.js, unsafe/helpers/resolveConfig.js) directly with plain configs and no own proxy or paramsSerializer, can inherit polluted proxy values (routing requests through an attacker-controlled proxy) or paramsSerializer values (attacker-controlled URL serialization). These low-level gadgets do not reproduce through normal high-level axios calls on 1.15.2+. The issue is fixed in axios 1.18.0 and 0.33.0.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
CWE-1321
Vulnerability Title
Axios 输入验证错误漏洞
Vulnerability Description
Axios是Axios团队开源的一款基于Promise(异步编程的一种解决方案)的HTTP客户端。 Axios 1.18.0之前版本和0.33.0之前版本存在输入验证错误漏洞,该漏洞源于原型污染gadgets,当Object.prototype已被污染时,在无请求体方法别名中通过(config || {}).data读取继承数据,可能导致攻击者控制请求正文或通过攻击者控制的代理路由请求。
CVSS Information
N/A
Vulnerability Type
N/A