Skip to content

updat eaxios version#16

Open
hilanatanson wants to merge 5 commits into
masterfrom
update_axios_version
Open

updat eaxios version#16
hilanatanson wants to merge 5 commits into
masterfrom
update_axios_version

Conversation

@hilanatanson
Copy link
Copy Markdown

axios is a promise-based HTTP client for the browser and Node.js.

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) due to inserting the X-XSRF-TOKEN header using the secret XSRF-TOKEN cookie value in all requests to any server when the XSRF-TOKEN}}0 cookie is available, and the {{withCredentials setting is turned on. If a malicious user manages to obtain this value, it can potentially lead to the XSRF defence mechanism bypass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant