QID 983771
QID 983771: Nodejs (npm) Security Update for hapi (GHSA-cqr7-78pj-3g7j)
Versions 2.0.x and 2.1.x of hapi are vulnerable to a denial of service attack via a file descriptor leak. When triggered repeatedly, this leak will cause the server to run out of file descriptors and the node process to die. The effort required to take down a server depends on the process file descriptor limit. No other side effects or exploits have been identified. ## Recommendation - Please upgrade to version 2.2.x or above as soon as possible.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cqr7-78pj-3g7j for updates pertaining to this vulnerability.
Vendor References
- GHSA-cqr7-78pj-3g7j -
github.com/advisories/GHSA-cqr7-78pj-3g7j
CVEs related to QID 983771
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cqr7-78pj-3g7j | hapi |
|