We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
axios versions before 1.6.8 depends on follow-redirects before 1.15.6, which could leak the proxy authentication credentials
axios/axios#6300
CVE-2024-39338: Server-Side Request Forgery in axios
5.4.9
No response
The text was updated successfully, but these errors were encountered:
fffab0f
Thanks for reporting that. Axios has been updated to v1.7.7 for the next release.
Sorry, something went wrong.
Craft 5.4.10 is out with that Axios update.
No branches or pull requests
What happened?
Description
axios versions before 1.6.8 depends on follow-redirects before 1.15.6, which could leak the proxy authentication credentials
axios/axios#6300
CVE-2024-39338: Server-Side Request Forgery in axios
Steps to reproduce
Craft CMS version
5.4.9
PHP version
No response
Operating system and version
No response
Database type and version
No response
Image driver and version
No response
Installed plugins and versions
The text was updated successfully, but these errors were encountered: