Lucene search

K
osvGoogleOSV:CVE-2020-28168
HistoryNov 06, 2020 - 8:15 p.m.

CVE-2020-28168

2020-11-0620:15:13
Google
osv.dev
4

6.6 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

68.3%

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

6.6 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

68.3%