Description
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security restrictions (like origin) would have those restrictions overridden by less restrictive defaults (e.g. origin defaults to all origins `*`).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1119 | When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security restrictions (like origin) would have those restrictions overridden by less restrictive defaults (e.g. origin defaults to all origins `*`). |
Github GHSA |
GHSA-j3g2-m5jj-6336 | Unsafe Merging of CORS Configuration Conflict in hapi |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-17T02:27:19.677Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2015-9243
No data.
Status : Modified
Published: 2018-05-29T20:29:00.547
Modified: 2024-11-21T02:40:07.943
Link: CVE-2015-9243
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA