Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| axios(npm) | 0 | 0.21.1 | N/A |
CVSS Metrics