Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade axios to version 1.20.0 or higher.
axios is a promise-based HTTP client for the browser and Node.js.
Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization in lib/helpers/shouldBypassProxy.js, which matches NO_PROXY entries by exact host or IP and has no parsing for CIDR notation, so an entry such as 127.0.0.0/8 or 10.0.0.0/8 never matches and the request is routed through the configured proxy. An attacker able to observe or operate that proxy can read internal hostnames, request URLs, headers, and any credentials those requests carry, by receiving traffic the deployment intended to keep direct. This requires a Node.js deployment with HTTP_PROXY or HTTPS_PROXY set, at least one NO_PROXY entry written in CIDR form, and a proxy sitting outside the intended trust boundary, and exact host or IP entries in NO_PROXY are matched correctly.
Note: This is only exploitable when requests are configured with proxy: false.
This vulnerability can be avoided by writing NO_PROXY entries for sensitive destinations as exact hosts or IP addresses rather than CIDR ranges.