漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
axios before 0.33.0 Prototype Pollution via nested option objects
Vulnerability Description
axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain objects such as auth and paramsSerializer are cloned into ordinary objects and read without own-property checks. When an application passes placeholder nested objects such as auth: {} or paramsSerializer: {}, inherited username/password values can cause silent injection of an Authorization: Basic header, and inherited encode/serialize values can alter query-string serialization (full serializer replacement requires a function-valued pollution primitive). This is exploitable only in the presence of pre-existing prototype pollution.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Vulnerability Type
CWE-1321
Vulnerability Title
Axios 输入验证错误漏洞
Vulnerability Description
Axios是Axios团队开源的一款基于Promise(异步编程的一种解决方案)的HTTP客户端。 Axios 0.33.0之前版本和1.18.0版本之前的1.x版本存在输入验证错误漏洞,该漏洞源于在JavaScript进程的Object.prototype已被其他组件污染时,未检查嵌套请求选项对象(如auth和paramsSerializer)的自身属性而读取继承属性,可能导致静默注入Authorization: Basic标头或改变查询字符串序列化。
CVSS Information
N/A
Vulnerability Type
N/A