CVE-2020-28168
published 2020-11-06CVE-2020-28168: Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
2.32%
81.7th percentile
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axios | axios | >= 0 < 0.21.1 | 0.21.1 |
| axios | axios | 0.19.0 – 0.21.0 | — |
| debian | node-axios | < node-axios 0.21.1+dfsg-1 (bookworm) | node-axios 0.21.1+dfsg-1 (bookworm) |
| siemens | sinec_ins | < 1.0 | 1.0 |
| siemens | sinec_ins | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Subnet Solutions Inc. PowerSYSTEM Center
cisa_ics·2024-10-03·CVSS 5.9
[MEDIUM] Subnet Solutions Inc. PowerSYSTEM Center
ICS Advisory
##
Subnet Solutions Inc. PowerSYSTEM Center
Release DateOctober 03, 2024
Alert CodeICSA-24-277-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Subnet Solutions Inc.
- Equipment: PowerSYSTEM Center
- Vulnerabilities: Server-Side Request Forgery (SSRF), Inefficient Regular Expression Complexity, Cross-Site Request Forgery (CSRF)
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in an attacker bypassing a proxy, creating a denial-of-service condition, or viewing sensitive information.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions
CISA ICS
Siemens SINEC INS
cisa_ics·2022-09-15·CVSS 7.8
[HIGH] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedSeptember 15, 2022
Alert CodeICSA-22-258-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Input Validation, Integer Overflow or Wraparound, Uncontrolled Resource Consumption, Command Injection, Inadequate Encryption Strength, Missing Encryption of Sensitive Data, Improper Restriction of Operations Within the Bounds of a Memory Buffer, Exposure of Private Personal Information to an Unauthorized Actor, Open Redirect, Improper Resour
Red Hat
nodejs-axios: allows an attacker to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address
vendor_redhat·2020-10-29·CVSS 5.9
CVE-2020-28168 [MEDIUM] CWE-918 nodejs-axios: allows an attacker to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address
nodejs-axios: allows an attacker to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
A flaw was found in nodejs-axios. The Axios NPM package contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Statement: Whilst in OpenShift Container Platform (OCP) the openshift4/ose-console container does include the vulnerable axios library, it does not use the vulnerable proxy functionality. Additionally, t
Debian
CVE-2020-28168: node-axios - Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerabi...
vendor_debian·2020·CVSS 5.9
CVE-2020-28168 [MEDIUM] CVE-2020-28168: node-axios - Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerabi...
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
Scope: local
bookworm: resolved (fixed in 0.21.1+dfsg-1)
bullseye: resolved (fixed in 0.21.1+dfsg-1)
forky: resolved (fixed in 0.21.1+dfsg-1)
sid: resolved (fixed in 0.21.1+dfsg-1)
trixie: resolved (fixed in 0.21.1+dfsg-1)
OSV
Axios vulnerable to Server-Side Request Forgery
osv·2021-01-04
CVE-2020-28168 [MEDIUM] Axios vulnerable to Server-Side Request Forgery
Axios vulnerable to Server-Side Request Forgery
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
GHSA
Axios vulnerable to Server-Side Request Forgery
ghsa·2021-01-04
CVE-2020-28168 [MEDIUM] CWE-918 Axios vulnerable to Server-Side Request Forgery
Axios vulnerable to Server-Side Request Forgery
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
OSV
CVE-2020-28168: Axios NPM package 0
osv·2020-11-06·CVSS 5.9
CVE-2020-28168 [MEDIUM] CVE-2020-28168: Axios NPM package 0
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/axios/axios/issues/3369https://lists.apache.org/thread.html/r25d53acd06f29244b8a103781b0339c5e7efee9099a4d52f0c230e4a%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r954d80fd18e9dafef6e813963eb7e08c228151c2b6268ecd63b35d1f%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rdfd2901b8b697a3f6e2c9c6ecc688fd90d7f881937affb5144d61d6e%40%3Ccommits.druid.apache.org%3Ehttps://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/axios/axios/issues/3369https://lists.apache.org/thread.html/r25d53acd06f29244b8a103781b0339c5e7efee9099a4d52f0c230e4a%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r954d80fd18e9dafef6e813963eb7e08c228151c2b6268ecd63b35d1f%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rdfd2901b8b697a3f6e2c9c6ecc688fd90d7f881937affb5144d61d6e%40%3Ccommits.druid.apache.org%3E
2020-11-06
Published