๐Ÿšจ [security][js] ์—…๊ทธ๋ ˆ์ด๋“œ axios:0.19.2โ†’ 0.21.1(์ „๋ฌธ)

5156 ๋‹จ์–ด mshauri

๋ฌ˜์‚ฌ

๐Ÿšจ ํ˜„์žฌ ์˜์กด ํ•ญ๋ชฉ์— ์•Œ๋ ค์ง„ ๋ณด์•ˆ ๊ฒฐํ•จ์ด ์žˆ์Šต๋‹ˆ๋‹ค๐Ÿšจ
์ด ์˜์กด ํ•ญ๋ชฉ ์—…๋ฐ์ดํŠธ๋Š” ์ด๋ฏธ ์•Œ๋ ค์ง„ ๋ณด์•ˆ ๋นˆํ‹ˆ์„ ๋ณต๊ตฌํ–ˆ์Šต๋‹ˆ๋‹ค.์•„๋ž˜์˜ ์ƒ์„ธํ•œ ์ •๋ณด๋ฅผ ๋ณด๊ณ  ๊ทธ ์˜ํ–ฅ์„ ์ž์„ธํžˆ ํ‰๊ฐ€ํ•ด ์ฃผ์‹ญ์‹œ์˜ค.์šฐ๋ฆฌ๋Š” ๊ฐ€๋Šฅํ•œ ํ•œ ๋นจ๋ฆฌ ๊ทธ๊ฒƒ์„ ํ•ฉ๋ณ‘ํ•˜๊ณ  ๋ฐฐ์น˜ํ•  ๊ฒƒ์„ ๊ฑด์˜ํ•ฉ๋‹ˆ๋‹ค.
๋‹ค์Œ์€ ์—…๊ทธ๋ ˆ์ด๋“œ์— ๋Œ€ํ•ด ์•Œ์•„์•ผ ํ•  ๋ชจ๋“  ์ •๋ณด์ž…๋‹ˆ๋‹ค.์ด ์š”์ฒญ์„ ํ†ตํ•ฉํ•˜๊ธฐ ์ „์— ๋ณ€๊ฒฝ๋œ ๋‚ด์šฉ๊ณผ ํ…Œ์ŠคํŠธ ๊ฒฐ๊ณผ๋ฅผ ์ž์„ธํžˆ ๋ณด์‹ญ์‹œ์˜ค.

๋ญ๊ฐ€ ๋ฐ”๋€Œ์—ˆ์–ด?


โœณ๏ธ axios๏ผˆ0.19.2โ†’ 0.21.1)ยทํ™˜๋งคยท๋ณ€๊ฒฝ๊ธฐ๋ก


์•ˆ์ „ ์ž๋ฌธ๐Ÿšจ

๐Ÿšจ Axios์˜ ์„œ๋ฒ„์ธก ์œ„์กฐ ์š”์ฒญ


Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.


๋ฆด๋ฆฌ์ฆˆ ๋…ธํŠธ

0.21.0


0.21.0(2020๋…„ 10์›” 23์ผ)

Fixes and Functionality:

  • Fixing requestHeaders.Authorization (#3287)
  • Fixing node types (#3237)
  • Fixing axios.delete ignores config.data (#3282)
  • Revert "Fixing overwrite Blob/File type as Content-Type in browser. (#1773)" (#3289)
  • Fixing an issue that type 'null' and 'undefined' is not assignable to validateStatus when typescript strict option is enabled (#3200)

Internal and Tests:

  • Lock travis to not use node v15 (#3361)

Documentation:

  • Fixing simple typo, existant -> existent (#3252)
  • Fixing typos (#3309)

Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:


0.20.0


Release of 0.20.0-pre as a full release with no other changes.


์ด๊ฒŒ ํ‹€๋ฆฐ ๊ฒƒ ๊ฐ™๋‚˜์š”?Please let us know.
์–ธ์•ฝ
See the full diff on Github . ์ƒˆ๋กœ์šด ๋ฒ„์ „์˜ ์ฐจ์ด๋Š” ์šฐ๋ฆฌ๊ฐ€ ์ด๊ณณ์—์„œ ๋ณด์—ฌ์ค€ ๊ฒƒ๋ณด๋‹ค ๋” ๋งŽ๋‹ค.
Depfu Status
Depfu ๋ถ„๊ธฐ์— ์ปค๋ฐ‹์„ ์ถ”๊ฐ€ํ•˜์ง€ ์•Š๋Š” ํ•œ ์ด PR์ด ์ถฉ๋Œํ•˜์ง€ ์•Š๋„๋ก ์ž๋™์œผ๋กœ ์œ ์ง€๋ฉ๋‹ˆ๋‹ค.@depfu rebase ์ฃผ์„์„ ์‚ฌ์šฉํ•˜์—ฌ ์ˆ˜๋™์œผ๋กœ ํ„ฐ์น˜ํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.
๋ชจ๋“  Depfu ์ฃผ์„ ๋ช…๋ น
@โ€‹depfu rebase
Rebases against your default branch and redoes this update
@โ€‹depfu recreate
Recreates this PR, overwriting any edits that you've made to it
@โ€‹depfu merge
Merges this PR once your tests are passing and conflicts are resolved
@โ€‹depfu close
Closes this PR and deletes the branch
@โ€‹depfu reopen
Restores the branch and reopens this PR (if it's closed)
@โ€‹depfu pause
Ignores all future updates for this dependency and closes this PR
@โ€‹depfu pause [minor|major]
Ignores all future minor/major updates for this dependency and closes this PR
@โ€‹depfu resume
Future versions of this dependency will create PRs again (leaves this PR as is)

ํ† ๋ก  #1

๋Š” #277๋กœ ๋งˆ๊ฐํ–ˆ๋‹ค.

์ข‹์€ ์›นํŽ˜์ด์ง€ ์ฆ๊ฒจ์ฐพ๊ธฐ