hapi-auth-jwt2@4.7.2 vulnerabilities

Hapi.js Authentication Plugin/Scheme using JSON Web Tokens (JWT)

  • latest version

    10.7.0

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the hapi-auth-jwt2 package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Authentication Bypass in Try Mode

    Authentication bypass issues exist in hapi-auth-jwt2 version 5.1.1, when try authentication mode is used, request.auth.isAuthenticated will be set to true for unauthenticated users.

    How to fix Authentication Bypass in Try Mode?

    Upgrade to version 5.1.2 or greater.

    <5.1.2