QID 984092
QID 984092: Nodejs (npm) Security Update for hapi (GHSA-j3g2-m5jj-6336)
Versions of `hapi` prior to 11.1.4 are affected by a vulnerability that causes route-level CORS configuration to override connection-level or server-level CORS defaults. This may result in a situation where CORS permissions are less restrictive than intended. ## Recommendation Update hapi to version 11.1.4 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-j3g2-m5jj-6336 for updates pertaining to this vulnerability.
Vendor References
- GHSA-j3g2-m5jj-6336 -
github.com/advisories/GHSA-j3g2-m5jj-6336
CVEs related to QID 984092
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j3g2-m5jj-6336 | hapi |
|