Skip to content

2 High Severity Vulnerabilities #5835

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
Mu-Gee opened this issue Mar 17, 2025 · 0 comments
Open

2 High Severity Vulnerabilities #5835

Mu-Gee opened this issue Mar 17, 2025 · 0 comments
Labels

Comments

@Mu-Gee
Copy link

Mu-Gee commented Mar 17, 2025

Describe the bug
axios <1.8.2
Severity: high
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL

To Reproduce
Steps to reproduce the behavior:

  1. npm install
  2. npm audit

Expected behavior
Expected a clean install with all packages updated but some dependencies seem to depend on other that have been found to be vulnerable.

Environment (please complete the following information):

  • AdminLTE Version: [4.0.0-beta3]
  • Operating System: [Windows 10]
  • Browser (Version): [Chrome]

Additional context
node_modules/axios
bundlewatch *
Depends on vulnerable versions of axios
node_modules/bundlewatch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant