PT-2025-10093 · Axios+3 · Axios+3

Lambdasawa

·

Published

2024-06-24

·

Updated

2026-04-30

·

CVE-2025-27152

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: axios versions 1.0.0 through 1.8.1 Bamboo Data Center and Server versions 9.6.1 through 11.0.0
Description: A Server-Side Request Forgery (SSRF) vulnerability exists in axios when handling absolute URLs instead of protocol-relative URLs. Even with a baseURL configured, axios may send requests to the specified absolute URL, potentially leading to SSRF and credential leakage. This impacts both server-side and client-side usage. The vulnerability allows attackers to access internal network resources and potentially access sensitive credentials. Millions of systems may be affected.
Recommendations: Upgrade axios to version 1.8.2 or later. Bamboo Data Center and Server 9.6: Upgrade to a release greater than or equal to 9.6.20. Bamboo Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.12. Bamboo Data Center and Server 11.0: Upgrade to a release greater than or equal to 11.0.8.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-02726
CVE-2025-27152
GHSA-JR5F-V2JV-69X6
OPENSUSE-SU-2025:15307-1
OPENSUSE-SU-2025_1227-1
OPENSUSE-SU-2025_1326-1
SUSE-SU-2025:01326-1
SUSE-SU-2025:1227-1
SUSE-SU-2025:1326-1

Affected Products

Bamboo
Debian
Suse
Axios