Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot Alert: Server-Side Request Forgery in axios #686

Open
JennaySDavis opened this issue Aug 15, 2024 · 2 comments
Open

Dependabot Alert: Server-Side Request Forgery in axios #686

JennaySDavis opened this issue Aug 15, 2024 · 2 comments

Comments

@JennaySDavis
Copy link
Contributor

Axios 1.7.2 allows SSRF via unexpected behavior where requests for path-relative URLs get processed as protocol-relative URLs.

@JennaySDavis
Copy link
Contributor Author

#686 Acceptance Criteria

Pass/Fail Description
Pass Full Regression Testing of Program Website

Comments/Additional Notes
N/A

ADA Compliance (Automated scan via Chrome Lighthouse)

Criteria Score
Performance 99
Accessibility 100
Best Practices 100

Passed 08/19/2024 - JSD

john-labbate added a commit that referenced this issue Aug 22, 2024
Convert PDF: Fleet > Helpful Hints #586
Convert PDF: Purchase > Helpful Hints #584
Convert PDF: Helpful Hints for Purchase Account Use #605
Convert PDF: Helpful Hints for Fleet Account Use #607
Convert PDF: Helpful Hints for Travel Account Use #606
California Tax #688
Dependabot Alert: Server-Side Request Forgery in axios #686
Update to the latest version of USWDS 3.8.2 | Program #681
Citi Bank Address #662
Update Forum 2025 #655
Replace Audit PDF DOI #667
Replace HUD Travel Audit PDF #663
Replace SSA Audit PDF #668
Replace GSA OIG Audit PDF #666
GSA 2018 Audit Replace PDF #665
2019 Audit DOD Replace PDF #664
@johnbeallgsa
Copy link
Contributor

Thanks for explaining this in the Demo. Moving to Done.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants