In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-Side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade Chainguard
tileserver-gl-fips
to version 5.1.3-r2 or higher.
Note: Versions mentioned in the description apply only to the upstream tileserver-gl-fips
package and not the tileserver-gl-fips
package as distributed by Chainguard
.
See How to fix?
for Chainguard
relevant fixed versions and status.
axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.