PT-2025-10093 · Axios+3 · Axios+3
Lambdasawa
·
Published
2024-06-24
·
Updated
2026-04-30
·
CVE-2025-27152
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
axios versions 1.0.0 through 1.8.1
Bamboo Data Center and Server versions 9.6.1 through 11.0.0
Description:
A Server-Side Request Forgery (SSRF) vulnerability exists in axios when handling absolute URLs instead of protocol-relative URLs. Even with a
baseURL configured, axios may send requests to the specified absolute URL, potentially leading to SSRF and credential leakage. This impacts both server-side and client-side usage. The vulnerability allows attackers to access internal network resources and potentially access sensitive credentials. Millions of systems may be affected.Recommendations:
Upgrade axios to version 1.8.2 or later.
Bamboo Data Center and Server 9.6: Upgrade to a release greater than or equal to 9.6.20.
Bamboo Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.12.
Bamboo Data Center and Server 11.0: Upgrade to a release greater than or equal to 11.0.8.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bamboo
Debian
Suse
Axios