Known Vulnerabilities for products from Hapijs

Listed below are 8 of the newest known vulnerabilities associated with the vendor "Hapijs".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2020-36604 json hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function. 8.1 - HIGH 2022-09-23 2023-11-07
CVE-2018-3728 json hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerabili... 8.8 - HIGH 2018-03-30 2019-10-09
CVE-2017-16025 json Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denia... 5.9 - MEDIUM 2018-06-04 2019-10-09
CVE-2017-16013 json hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` head... 7.5 - HIGH 2018-06-04 2019-10-09
CVE-2015-9243 json When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and whe... 5.9 - MEDIUM 2018-05-29 2019-10-09
CVE-2015-9241 json Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raise... 7.5 - HIGH 2018-05-29 2019-10-09
CVE-2015-9236 json Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent h... 5.3 - MEDIUM 2018-05-31 2019-10-09
CVE-2014-7193 json The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler ha... 5.8 - MEDIUM 2014-12-25 2021-07-19

Known software with vulnerabilities from Hapijs

Type Vendor Product Version
ApplicationHapijsCrumb2.2.0
ApplicationHapijsHapi0.0.1
ApplicationHapijsHoek0.0.6
ApplicationHapijsNes0.2.0