Skip to content

Upgrade axios to resolve CVE-2024-39338 #2193

@jayknyn

Description

@jayknyn

Hi, the latest @slack/bolt@3.19.0 is using axios@1.7.2 that allows Server-Side Request Forgery via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. This high vulnerability is failing in our CI pipeline and blocking releases.

Requirements
Axios version should be upgraded to 1.7.3 to address CVE-2024-39338

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions