Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update axios version. CORS Vulnerability #1776

Closed
RyanGSampson opened this issue Jan 22, 2024 · 3 comments
Closed

Update axios version. CORS Vulnerability #1776

RyanGSampson opened this issue Jan 22, 2024 · 3 comments

Comments

@RyanGSampson
Copy link

Versions:

  • @inertiajs/core version: #.#.#
  • @inertiajs/vue2 version: #.#.#
  • @inertiajs/vue3 version: #.#.#
  • @inertiajs/react version: #.#.#
  • @inertiajs/svelte version: #.#.#

Describe the problem:

Ineria core running on axios 1.2.0
Please update to 1.6.5

Steps to reproduce:

run npm audit

npm audit report

axios 0.8.1 - 1.5.1
Severity: moderate
Axios Cross-Site Request Forgery Vulnerability - GHSA-wf5p-g6vw-rhxx
No fix available
node_modules/@inertiajs/inertia/node_modules/axios
@inertiajs/inertia *
Depends on vulnerable versions of axios
node_modules/@inertiajs/inertia
@inertiajs/inertia-vue3 *
Depends on vulnerable versions of @inertiajs/inertia
node_modules/@inertiajs/inertia-vue3

3 moderate severity vulnerabilities

Some issues need review, and may require choosing
a different dependency.

@vitalijalbu
Copy link

@reinink any future updates on this??

@shengslogar
Copy link

Should be addressed by #1723

@reinink
Copy link
Member

reinink commented Feb 26, 2024

Yep, thanks @shengslogar — this one has been fixed in #1723 👍

@reinink reinink closed this as completed Feb 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants