Skip to content

[5.x]: upgrade vulnerable axios 1.15.1 #19053

@AmsalSugihan

Description

@AmsalSugihan

What happened?

Description

The current version of axios (1.15.1) contains multiple critical and high-severity security vulnerabilities that should be addressed. Please upgrade to version 1.16.0 or higher.

The current version contains 10 known vulnerabilities (1 critical, 4 high, 5 medium severity) affecting:

  • Proxy credential handling
  • Request manipulation and SSRF attacks
  • Prototype pollution attacks
  • Resource exhaustion

For full vulnerability details, see: https://security.snyk.io/package/npm/axios/1.15.1

Steps to reproduce

  1. Navigate to the following URL: https://example.com/admin/login
  2. Open the browser's built in developer tools
  3. Enter the following string into the JavaScript console: axios.VERSION
  4. Note that the application includes a version of axios 1.15.1 which has known security issues associated with it

Craft CMS version

5.10.5

PHP version

No response

Operating system and version

No response

Database type and version

No response

Image driver and version

No response

Installed plugins and versions

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions