VYPR
Vendor

hapijs

Products
4
CVEs
4
Across products
4
Status
Private

Products

4

Recent CVEs

4
  • CVE-2020-36604Sep 23, 2022
    risk 0.00cvss epss 0.01

    hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.

  • CVE-2017-16025Jun 4, 2018
    risk 0.00cvss epss 0.00

    Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid…

  • CVE-2014-10068May 29, 2018
    risk 0.00cvss epss 0.00

    The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, even when `showHidden` is false.

  • CVE-2014-7193Dec 25, 2014
    risk 0.00cvss epss 0.00

    The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtain sensitive information, and potentially obtain the ability to spoof requests to non-CORS routes,…