GHSA-23vw-mhv5-grv5
HIGHVersions of @hapi/hapi prior to 18.4.1 or 19.1.1 are vulnerable to Denial of Service. The CORS request handler has a vulnerability which will cause the function to throw a system error if the header contains some invalid values. If no unhandled exception handler is available, the application will exist, allowing an attacker to shut down services.
- Affected
- >= 19.0.0, < 19.1.1, < 18.4.1
- Fixed in
- 19.1.1
- Published
- 2020-09-03
- Source
- github