Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-11506

Axios - CVE-2025-27152

    XporterXMLWordPrintable

Details

    • Bug
    • Status: Code Review
    • Critical
    • Resolution: Unresolved
    • Xray DC 8.2.3
    • Continuous Delivery
    • Security
    • We should update both the webjar and npm package.

      No current risk. Not exploitable.

      Just for hygiene.

    • UNCOVERED

    Description

      Overview

      The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios.

       

      Affected Package

      Axios@1.7.7

       

      Remediation

      Upgrade to axios to 1.8.2 or 1.12.0

      Attachments

        Issue Links

          Activity

            People

              pamp Paulo Pereira
              roy.mehmood Raza Mehmood
              Votes:
              1 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated: