GSA / smartpay-website

SmartPay website
https://federalist-ab31a10d-375d-4040-9324-1ae94e8a36b9.sites.pages.cloud.gov/site/gsa/smartpay-website/
3 stars 0 forks source link

Dependabot Alert: Server-Side Request Forgery in axios #686

Open JennaySDavis opened 3 months ago

JennaySDavis commented 3 months ago

Axios 1.7.2 allows SSRF via unexpected behavior where requests for path-relative URLs get processed as protocol-relative URLs.

JennaySDavis commented 3 months ago

#686 Acceptance Criteria

Pass/Fail Description
Pass Full Regression Testing of Program Website

Comments/Additional Notes N/A

ADA Compliance (Automated scan via Chrome Lighthouse)

Criteria Score
Performance 99
Accessibility 100
Best Practices 100

Passed 08/19/2024 - JSD

johnbeallgsa commented 2 months ago

Thanks for explaining this in the Demo. Moving to Done.