๐จ [security][js] ์ ๊ทธ๋ ์ด๋ axios:0.19.2โ 0.21.1(์ ๋ฌธ)
๋ฌ์ฌ
๐จ ํ์ฌ ์์กด ํญ๋ชฉ์ ์๋ ค์ง ๋ณด์ ๊ฒฐํจ์ด ์์ต๋๋ค๐จ์ด ์์กด ํญ๋ชฉ ์ ๋ฐ์ดํธ๋ ์ด๋ฏธ ์๋ ค์ง ๋ณด์ ๋นํ์ ๋ณต๊ตฌํ์ต๋๋ค.์๋์ ์์ธํ ์ ๋ณด๋ฅผ ๋ณด๊ณ ๊ทธ ์ํฅ์ ์์ธํ ํ๊ฐํด ์ฃผ์ญ์์ค.์ฐ๋ฆฌ๋ ๊ฐ๋ฅํ ํ ๋นจ๋ฆฌ ๊ทธ๊ฒ์ ํฉ๋ณํ๊ณ ๋ฐฐ์นํ ๊ฒ์ ๊ฑด์ํฉ๋๋ค.
๋ค์์ ์ ๊ทธ๋ ์ด๋์ ๋ํด ์์์ผ ํ ๋ชจ๋ ์ ๋ณด์ ๋๋ค.์ด ์์ฒญ์ ํตํฉํ๊ธฐ ์ ์ ๋ณ๊ฒฝ๋ ๋ด์ฉ๊ณผ ํ ์คํธ ๊ฒฐ๊ณผ๋ฅผ ์์ธํ ๋ณด์ญ์์ค.
๋ญ๊ฐ ๋ฐ๋์์ด?
โณ๏ธ axios๏ผ0.19.2โ 0.21.1)ยทํ๋งคยท๋ณ๊ฒฝ๊ธฐ๋ก
์์ ์๋ฌธ๐จ
๐จ Axios์ ์๋ฒ์ธก ์์กฐ ์์ฒญ
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
๋ฆด๋ฆฌ์ฆ ๋ ธํธ
0.21.0
0.21.0(2020๋ 10์ 23์ผ)
Fixes and Functionality:
- Fixing requestHeaders.Authorization (#3287)
- Fixing node types (#3237)
- Fixing axios.delete ignores config.data (#3282)
- Revert "Fixing overwrite Blob/File type as Content-Type in browser. (#1773)" (#3289)
- Fixing an issue that type 'null' and 'undefined' is not assignable to validateStatus when typescript strict option is enabled (#3200)
Internal and Tests:
- Lock travis to not use node v15 (#3361)
Documentation:
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
- Allan Cruz [email protected]
- George Cheng [email protected]
- Jay [email protected]
- Kevin Kirsche [email protected]
- Remco Haszing [email protected]
- Taemin Shin [email protected]
- Tim Gates [email protected]
- Xianming Zhong [email protected]
0.20.0
Release of 0.20.0-pre as a full release with no other changes.
์ด๊ฒ ํ๋ฆฐ ๊ฒ ๊ฐ๋์?Please let us know.
์ธ์ฝ
See the full diff on Github . ์๋ก์ด ๋ฒ์ ์ ์ฐจ์ด๋ ์ฐ๋ฆฌ๊ฐ ์ด๊ณณ์์ ๋ณด์ฌ์ค ๊ฒ๋ณด๋ค ๋ ๋ง๋ค.
Depfu ๋ถ๊ธฐ์ ์ปค๋ฐ์ ์ถ๊ฐํ์ง ์๋ ํ ์ด PR์ด ์ถฉ๋ํ์ง ์๋๋ก ์๋์ผ๋ก ์ ์ง๋ฉ๋๋ค.
@depfu rebase
์ฃผ์์ ์ฌ์ฉํ์ฌ ์๋์ผ๋ก ํฐ์นํ ์๋ ์์ต๋๋ค.๋ชจ๋ Depfu ์ฃผ์ ๋ช ๋ น
- @โdepfu rebase
- Rebases against your default branch and redoes this update
- @โdepfu recreate
- Recreates this PR, overwriting any edits that you've made to it
- @โdepfu merge
- Merges this PR once your tests are passing and conflicts are resolved
- @โdepfu close
- Closes this PR and deletes the branch
- @โdepfu reopen
- Restores the branch and reopens this PR (if it's closed)
- @โdepfu pause
- Ignores all future updates for this dependency and closes this PR
- @โdepfu pause [minor|major]
- Ignores all future minor/major updates for this dependency and closes this PR
- @โdepfu resume
- Future versions of this dependency will create PRs again (leaves this PR as is)
ํ ๋ก #1
๋ #277๋ก ๋ง๊ฐํ๋ค.Reference
์ด ๋ฌธ์ ์ ๊ดํ์ฌ(๐จ [security][js] ์ ๊ทธ๋ ์ด๋ axios:0.19.2โ 0.21.1(์ ๋ฌธ)), ์ฐ๋ฆฌ๋ ์ด๊ณณ์์ ๋ ๋ง์ ์๋ฃ๋ฅผ ๋ฐ๊ฒฌํ๊ณ ๋งํฌ๋ฅผ ํด๋ฆญํ์ฌ ๋ณด์๋ค https://github.com/bumi/mshauri/issues/236ํ ์คํธ๋ฅผ ์์ ๋กญ๊ฒ ๊ณต์ ํ๊ฑฐ๋ ๋ณต์ฌํ ์ ์์ต๋๋ค.ํ์ง๋ง ์ด ๋ฌธ์์ URL์ ์ฐธ์กฐ URL๋ก ๋จ๊ฒจ ๋์ญ์์ค.
์ฐ์ํ ๊ฐ๋ฐ์ ์ฝํ ์ธ ๋ฐ๊ฒฌ์ ์ ๋ (Collection and Share based on the CC Protocol.)
์ข์ ์นํ์ด์ง ์ฆ๊ฒจ์ฐพ๊ธฐ
๊ฐ๋ฐ์ ์ฐ์ ์ฌ์ดํธ ์์ง
๊ฐ๋ฐ์๊ฐ ์์์ผ ํ ํ์ ์ฌ์ดํธ 100์ ์ถ์ฒ ์ฐ๋ฆฌ๋ ๋น์ ์ ์ํด 100๊ฐ์ ์์ฃผ ์ฌ์ฉํ๋ ๊ฐ๋ฐ์ ํ์ต ์ฌ์ดํธ๋ฅผ ์ ๋ฆฌํ์ต๋๋ค