CyberRota Analysis
AI-GeneratedAxios versions 1.17.0 to 1.20.0 are vulnerable due to a flaw in the fetch adapter that allows it to bypass the maxRedirects: 0 policy, leading to unintended redirection of requests. This can result in unauthorized access to internal responses or state-changing endpoints, posing a significant security risk. Developers and organizations using affected versions of Axios should prioritize upgrading to version 1.20.0 or later to mitigate this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch implementation follows the redirect instead of returning the redirect response unchanged. The redirected request can access internal responses or reach state-changing internal endpoints despite redirects being disabled. This issue is fixed in version 1.20.0.