Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-36604 | hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function. hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function. NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2017-16025 | Nes is a websocket extension library for hapi. Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will cause the node process to error out. NVD description · AI analysis pending | 5.9 | 2% |
| — | ||
| CVE-2017-16013 | hapi is a web and services application framework. hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to hang the client connection until the timeout period is reached. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2018-3728 | hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects. NVD description · AI analysis pending | 8.8 | 4% | PoC ×2 |
| — |