QID 980986
QID 980986: Nodejs (npm) Security Update for hapi-auth-jwt2 (GHSA-mg8r-9g6j-hwv9)
Versions of `hapi-auth-jwt2` prior to version 5.1.2 are affected by a complete authentication bypass vulnerability when in the `try` authentication mode.
## Recommendation
Update to version 5.1.2 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mg8r-9g6j-hwv9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-mg8r-9g6j-hwv9 -
github.com/advisories/GHSA-mg8r-9g6j-hwv9
CVEs related to QID 980986
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mg8r-9g6j-hwv9 | hapi-auth-jwt2 |
|