-
Notifications
You must be signed in to change notification settings - Fork 45
Closed
Description
Hello,
We're seeing a high audit alert on CloudConvert, which uses Axios version 0.28.1.
CloudConvert version: 2.3.7
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ high │ axios Requests Vulnerable To Possible SSRF and Credential │
│ │ Leakage via Absolute URL │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ axios │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=1.8.2 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ cloudconvert │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ cloudconvert > axios │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://www.npmjs.com/advisories/1102472 │
└───────────────┴──────────────────────────────────────────────────────────────┘
Could this possibly be patched up.
Thank you.
Metadata
Metadata
Assignees
Labels
No labels