GHSA-42xw-2xvc-qx8m

    Dashboard / Vulnerabilities / GHSA-42xw-2xvc-qx8m

    GHSA-42xw-2xvc-qx8m

    Published: 29 May 2019Last Modified: 8 Nov 2023

    Summary: Denial of Service in axios

    Details: Versions of `axios` prior to 0.18.1 are vulnerable to Denial of Service. If a request exceeds the `maxContentLength` property, the package prints an error but does not stop the request. This may cause high CPU usage and lead to Denial of Service. ## Recommendation Upgrade to 0.18.1 or later.

    Affected packages

    Package

    Name: axios

    Purl: pkg:npm/axios

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.18.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High