This repository was archived by the owner on Feb 13, 2024. It is now read-only.
This repository was archived by the owner on Feb 13, 2024. It is now read-only.
Upgrade axios to >=0.21.1 to fix high vulnerability #258
Closed
Description
Hi,
could we ask to update the axios
version to avoid the SSRF vulnerability?
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Server-Side Request Forgery │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ axios │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=0.21.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ analytics-node │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ analytics-node > axios │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/1594 │
└───────────────┴──────────────────────────────────────────────────────────────┘
Metadata
Metadata
Assignees
Labels
No labels