matthiaskoenig / pkdb

Pharmacokinetics database
https://alpha.pk-db.com
30 stars 6 forks source link

Axios security update & frontend dependency update #708

Closed matthiaskoenig closed 3 years ago

matthiaskoenig commented 3 years ago

CVE-2020-28168 high severity Vulnerable versions: < 0.21.1 Patched version: 0.21.1

Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.