Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SRCCLR-SID-21679: Veracode scan reporting "Cross-Site Scripting (XSS) Vulnerability in the axios library" #2463

Closed
tpag26 opened this issue Oct 14, 2019 · 3 comments

Comments

@tpag26
Copy link

tpag26 commented Oct 14, 2019

Veracode is reporting that all versions of axios (up to and including 0.19.0-beta.1) contain a XSS vulnerability. (CVSSv3: 6.1)

Very limited details available:
https://www.sourceclear.com/vulnerability-database/security/sca/vulnerability/sid-21679/summary

I suspect it is a false positive based on comments here. Would value any thoughts / input

Thanks

@yasuf
Copy link
Collaborator

yasuf commented Oct 14, 2019

I just made a PR, the last PR (#2451) I believe just wasn't returning or throwing an error when it detected a script in the URL, thanks for the heads up!

@yasuf
Copy link
Collaborator

yasuf commented Oct 15, 2019

@tpag26 can you close this issue, since this is a duplicate of #2447 ? I'll link the PR to that issue

@tpag26 tpag26 closed this as completed Oct 15, 2019
@tpag26
Copy link
Author

tpag26 commented Oct 15, 2019

Thanks @yasuf

@axios axios locked and limited conversation to collaborators May 22, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants