Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot Alert: Axios Cross-Site Request Forgery Vulnerability #161

Open
JennaySDavis opened this issue Jan 5, 2024 · 2 comments
Open

Comments

@JennaySDavis
Copy link

JennaySDavis commented Jan 5, 2024

Severity - Moderate

An issue discovered in Axios 0.8.1 through 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host, allowing attackers to view sensitive information.

@JennaySDavis
Copy link
Author

#161 Acceptance Criteria

Pass/Fail Description
Pass Execute Search; sam.gov returns results to 889 Tool

Comments/Additional Notes
*A minor issue with aria labels was located, affecting the accessibility score. See https://github.com/orgs/GSA/projects/116/views/3?pane=issue&itemId=51527311

ADA Compliance (Automated scan via Chrome Lighthouse)

Criteria Score
Performance 98
Accessibility 96
Best Practices 93

Passed 01/29/2024 - JSD

@LoraBradford
Copy link

Reviewed 889 tool, did not see any issues. Story #185 will fix the accessibility score. Thank you! Moving to done!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants