Description
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3051 | An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information. |
Github GHSA |
GHSA-wf5p-g6vw-rhxx | Axios Cross-Site Request Forgery Vulnerability |
References
History
Thu, 26 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Mar 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat advanced Cluster Security
|
|
| CPEs | cpe:/a:redhat:advanced_cluster_security:4.7::el8 | |
| Vendors & Products |
Redhat advanced Cluster Security
|
Tue, 13 Aug 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:container_native_virtualization:4.13::el9 |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-04T15:15:16.506Z
Reserved: 2023-10-14T00:00:00.000Z
Link: CVE-2023-45857
Updated: 2024-08-02T20:29:32.674Z
Status : Modified
Published: 2023-11-08T21:15:08.550
Modified: 2024-11-21T08:27:30.040
Link: CVE-2023-45857
OpenCVE Enrichment
No data.
EUVD
Github GHSA