1. axios 1.7.2 SSRF Vulnerability (CVE-2024-39338) Exposes Projects to Server-Side Request Forgery
A critical Server-Side Request Forgery (SSRF) vulnerability in the widely-used axios HTTP client library has been publicly disclosed, forcing a major security update across countless software projects. The flaw, tracked as CVE-2024-39338, resides in axios version 1.7.2 and allows an attacker to manipulate requests for ...