ended4월 14일· 1 sources

Axios 라이브러리의 헤더 주입(CRLF)을 악용한 클라우드 서버 권한 탈취 취약점

Why it matters

This vulnerability demonstrates how minor flaws in popular libraries like Axios can be weaponized into a critical cloud account takeover through complex attack chains. It highlights the persistent risk of Request Smuggling and the importance of securing internal metadata services like AWS IMDSv2 against malicious header injections.

1
Sources
+0
24h
Growth
154d
Active
AxiosCRLF injectionRequest SmugglingAWS IMDSv2IAM credentialsPrototype Pollution

Sources

Related Issues