-
Notifications
You must be signed in to change notification settings - Fork 89
Open
Description
The js lib run on a old version of axio with important security issue : "axios": "1.1.3".
You should consider moving to a new version of axios.
axios <=0.29.0 || 1.0.0 - 1.8.1
Severity: high
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
Axios Cross-Site Request Forgery Vulnerability - https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL - https://github.com/advisories/GHSA-jr5f-v2jv-69x6
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL - https://github.com/advisories/GHSA-jr5f-v2jv-69x6
No fix available
node_modules/@osmonauts/lcd/node_modules/axios
node_modules/axios
@dydxprotocol/v4-client-js *
Depends on vulnerable versions of @osmonauts/lcd
Depends on vulnerable versions of axios
node_modules/@dydxprotocol/v4-client-js
@osmonauts/lcd *
Depends on vulnerable versions of axios
node_modules/@osmonauts/lcd
3 high severity vulnerabilities
To address issues that do not require attention, run:
npm audit fix
Metadata
Metadata
Assignees
Labels
No labels