GHSA-66mv-xh68-h6v2
HIGHAffected versions of @commercial/hapi are vulnerable to Denial of Service. The CORS request handler has a vulnerability which will cause the function to throw a system error if the header contains some invalid values. If no unhandled exception handler is available, the application will exist, allowing an attacker to shut down services.
- Affected
- >= 18.0.0, < 18.4.1, >= 17.0.0, < 17.9.2, < 16.8.2, >=0, <16.8.2, >=17.0.0, <17.9.2, >=18.0.0, <18.4.1, >=19.0.0, <19.1.1
- Fixed in
- 18.4.1
- Published
- 2020-09-03
- Source
- github