An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Aug 2024 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:container_native_virtualization:4.13::el9 |
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-11-08T00:00:00
Updated: 2024-09-04T15:15:16.506Z
Reserved: 2023-10-14T00:00:00
Link: CVE-2023-45857
Vulnrichment
Updated: 2024-08-02T20:29:32.674Z
NVD
Status : Modified
Published: 2023-11-08T21:15:08.550
Modified: 2024-11-21T08:27:30.040
Link: CVE-2023-45857
Redhat