Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[playwright-qase-reporter] Mitigation of Axios Cross-Site Request Forgery Vulnerability in playwright-qase-reporter npm package #475

Open
bs-rezve opened this issue Dec 15, 2023 · 1 comment

Comments

@bs-rezve
Copy link

The npm package "playwright-qase-reporter" is currently vulnerable to a moderate Cross-Site Request Forgery (CSRF) issue in the Axios library, as identified by the npm audit advisory GHSA-wf5p-g6vw-rhxx.

Vulnerability Details

Severity: Moderate
Package: axios
Patched Version: >=1.6.0
Dependency Chain: playwright-qase-reporter > qaseio > axios
Advisory Link: GHSA-wf5p-g6vw-rhxx

image

Recommendation:

Update the Axios library in the "playwright-qase-reporter" npm package to version >=1.6.0 to mitigate the CSRF vulnerability.

Steps to Reproduce:

The vulnerability can be verified by running the npm audit command on the "playwright-qase-reporter" npm package.

Thanks

@stale stale bot added the wontfix This will not be worked on label Mar 15, 2024
@stale stale bot closed this as completed Mar 22, 2024
@NickVolynkin NickVolynkin reopened this Mar 22, 2024
@stale stale bot removed the wontfix This will not be worked on label Mar 22, 2024
@qase-tms qase-tms deleted a comment from stale bot Mar 22, 2024
@apis3445
Copy link

apis3445 commented Mar 24, 2024

Any updates to fix this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants