An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3051 | An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information. |
Github GHSA |
GHSA-wf5p-g6vw-rhxx | Axios Cross-Site Request Forgery Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Mar 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat advanced Cluster Security
|
|
| CPEs | cpe:/a:redhat:advanced_cluster_security:4.7::el8 | |
| Vendors & Products |
Redhat advanced Cluster Security
|
Tue, 13 Aug 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:container_native_virtualization:4.13::el9 |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-04T15:15:16.506Z
Reserved: 2023-10-14T00:00:00
Link: CVE-2023-45857
Updated: 2024-08-02T20:29:32.674Z
Status : Modified
Published: 2023-11-08T21:15:08.550
Modified: 2024-11-21T08:27:30.040
Link: CVE-2023-45857
OpenCVE Enrichment
No data.
EUVD
Github GHSA