CVE-2015-9243
29.05.2018, 20:29
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security restrictions (like origin) would have those restrictions overridden by less restrictive defaults (e.g. origin defaults to all origins `*`).Enginsight
Vendor | Product | Version |
---|---|---|
hapijs | hapi | 𝑥 < 11.1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration