Server-Side Request Forgery (SSRF) in axios - CVE-2020-28168

 

Server-Side Request Forgery (SSRF) in axios - CVE-2020-28168

Published: November 6, 2020 / Updated: January 4, 2021


Vulnerability identifier: #VU49251
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2020-28168
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

axios
BigBlueButton
IBM Integration Bus
IBM Sterling Control Center
SINEC INS
IBM Planning Analytics Workspace
IBM Cloud Pak System
IBM App Connect Enterprise

How to mitigate CVE-2020-28168

Install updates from vendor's website.

axios - update to 0.21.1
BigBlueButton - update to 2.2.32
SINEC INS - update to 1.0 SP2
IBM Planning Analytics Workspace - update to 2.0.93
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
IBM App Connect Enterprise - update to 11.0.0.11

External References

Related Security Bulletins