CVE-2023-45857
Axios CSRF Token Exposure Vulnerability
Description
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
INFO
Published Date :
Nov. 8, 2023, 9:15 p.m.
Last Modified :
Nov. 21, 2024, 8:27 a.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | MEDIUM | [email protected] |
Solution
- There is no known solution at this time.
Public PoC/Exploit Available at Github
CVE-2023-45857 has a 31 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2023-45857.
| URL | Resource |
|---|---|
| https://github.com/axios/axios/issues/6006 | Exploit Issue Tracking |
| https://security.netapp.com/advisory/ntap-20240621-0006/ | |
| https://github.com/axios/axios/issues/6006 | Exploit Issue Tracking |
| https://security.netapp.com/advisory/ntap-20240621-0006/ |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2023-45857 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2023-45857
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
An example repo which shows you how to ingest a JFrog report via SARIF through Sonarscanner
Dockerfile Shell JavaScript
Multi-ecosystem dependency security auditor for Claude Code. Noise filtering, auto-remediation, license compliance, SBOM generation.
None
JavaScript
Claude Code plugin: audit npm dependencies across a GitHub org or repo for CVEs and supply-chain risks
DevSecOps vulnerability monitoring platform — Trivy CVE scanning, React dashboard, GitHub Actions CI/CD, Kubernetes
JavaScript Dockerfile TypeScript HTML CSS Shell
Scan Node.js projects for vulnerable axios versions using live OSV API data — zero dependencies, CI-ready
JavaScript
None
JavaScript HTML TypeScript CSS
None
JavaScript Python Rust
Scan projects for CVEs in AI-generated dependencies. Zero API calls. Works offline.
Python
host ai agent baseline check
Shell
None
None
HTML JavaScript CSS
Demo app with known vulnerable dependencies for SCA vulnerability remediation using GitHub Copilot coding agent
OpenClaw Skills Library 2,510 Production-Ready Skills for AI Agent Automation Give your OpenClaw agent the complete puzzle. Modular, observable, and safe automation workflows for Ubuntu Linux systems. Built for professionals who need reliability.
None
C# Open Policy Agent
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2023-45857 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2023-45857 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 21, 2024
Action Type Old Value New Value Added Reference https://github.com/axios/axios/issues/6006 Added Reference https://security.netapp.com/advisory/ntap-20240621-0006/ -
CVE Modified by [email protected]
Jun. 21, 2024
Action Type Old Value New Value Added Reference MITRE https://security.netapp.com/advisory/ntap-20240621-0006/ [No types assigned] -
CVE Modified by [email protected]
May. 14, 2024
Action Type Old Value New Value -
Initial Analysis by [email protected]
Nov. 16, 2023
Action Type Old Value New Value Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Changed Reference Type https://github.com/axios/axios/issues/6006 No Types Assigned https://github.com/axios/axios/issues/6006 Exploit, Issue Tracking Added CWE NIST CWE-352 Added CPE Configuration OR *cpe:2.3:a:axios:axios:1.5.1:*:*:*:*:node.js:*:* -
CVE Received by [email protected]
Nov. 08, 2023
Action Type Old Value New Value Added Description An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information. Added Reference MITRE https://github.com/axios/axios/issues/6006 [No types assigned]