HackerOne / Hapi Node Module
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-16013 | hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown… | HIGH | 7.5 | Jun 4, 2018 |
| CVE-2015-9236 | Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-… | MEDIUM | 5.3 | May 31, 2018 |
| CVE-2015-9243 | When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included s… | MEDIUM | 5.9 | May 29, 2018 |
| CVE-2015-9241 | Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a HTTP 500 e… | HIGH | 7.5 | May 29, 2018 |
Showing 1 to 4 of 4 CVEs