Описание
Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to cookie. Submitting an invalid cookie on the websocket upgrade request will cause the node process to error out.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.4.0 (включая)
cpe:2.3:a:hapijs:nes:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 58%
0.00365
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-400
CWE-287
Связанные уязвимости
EPSS
Процентиль: 58%
0.00365
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-400
CWE-287