CVE-2019-10742

HIGH7.5EPSS 13.1%

Denial of Service in axios

發布日:2019/5/29修改日:2023/11/8
也稱為:GHSA-42xw-2xvc-qx8mDEBIAN-CVE-2019-10742

描述

Versions of `axios` prior to 0.18.1 are vulnerable to Denial of Service. If a request exceeds the `maxContentLength` property, the package prints an error but does not stop the request. This may cause high CPU usage and lead to Denial of Service. ## Recommendation Upgrade to 0.18.1 or later.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

參考連結(8)