When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security restrictions (like origin) would have those restrictions overridden by less restrictive defaults (e.g. origin defaults to all origins `*`).
Advisories
Source ID Title
EUVD EUVD EUVD-2020-1119 When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security restrictions (like origin) would have those restrictions overridden by less restrictive defaults (e.g. origin defaults to all origins `*`).
Github GHSA Github GHSA GHSA-j3g2-m5jj-6336 Unsafe Merging of CORS Configuration Conflict in hapi
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-09-17T02:27:19.677Z

Reserved: 2017-10-29T00:00:00

Link: CVE-2015-9243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-29T20:29:00.547

Modified: 2024-11-21T02:40:07.943

Link: CVE-2015-9243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses