Actions
Bug #26933
closedupdate axios npm package due to CVE
Description
CVE-2019-10742 More information
high severity
Vulnerable versions: <= 0.18.0
Patched version: 0.19.0
Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.
Updated by The Foreman Bot over 5 years ago
- Status changed from New to Ready For Testing
- Assignee set to Ohad Levy
- Pull request https://github.com/theforeman/foreman/pull/6816 added
Updated by Ohad Levy over 5 years ago
- Status changed from Ready For Testing to Closed
Applied in changeset 20d7866208b6e33e15f2985da8b6b8a9e3906bec.
Actions