Skip to content

Unsafe Merging of CORS Configuration Conflict in hapi

Moderate severity GitHub Reviewed Published Sep 1, 2020 to the GitHub Advisory Database • Updated Jan 9, 2023

Package

npm hapi (npm)

Affected versions

< 11.1.4

Patched versions

11.1.4

Description

Versions of hapi prior to 11.1.4 are affected by a vulnerability that causes route-level CORS configuration to override connection-level or server-level CORS defaults. This may result in a situation where CORS permissions are less restrictive than intended.

Recommendation

Update hapi to version 11.1.4 or later.

References

Reviewed Aug 31, 2020
Published to the GitHub Advisory Database Sep 1, 2020
Last updated Jan 9, 2023

Severity

Moderate

EPSS score

0.118%
(47th percentile)

Weaknesses

CVE ID

CVE-2015-9243

GHSA ID

GHSA-j3g2-m5jj-6336

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.