Skip to content

Conversation

@benpetty
Copy link
Contributor

@benpetty benpetty commented Apr 1, 2025

upgrade axios - Fixes #73

CVE-2024-39338

Server-Side Request Forgery in axios
GHSA-8hc4-vh64-cxmj

CVE-2025-27152

Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL GHSA-jr5f-v2jv-69x6

# CVE-2024-39338
Server-Side Request Forgery in axios
GHSA-8hc4-vh64-cxmj

# CVE-2025-27152
Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
GHSA-jr5f-v2jv-69x6
@benpetty benpetty changed the title High severity vulnerabilities in Axios fix: High severity vulnerabilities in Axios Apr 1, 2025
@hsluoyz hsluoyz changed the title fix: High severity vulnerabilities in Axios feat: upgrade axios dependency to v1.8.4 Apr 1, 2025
@hsluoyz hsluoyz merged commit 68f9852 into casdoor:master Apr 1, 2025
5 checks passed
@github-actions
Copy link

github-actions bot commented Apr 2, 2025

🎉 This PR is included in version 1.28.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

High severity vulnerabilities in axios dependency

2 participants