hapi-auth-jwt2@4.9.0 vulnerabilities

Hapi.js Authentication Plugin/Scheme using JSON Web Tokens (JWT)

Direct Vulnerabilities

Known vulnerabilities in the hapi-auth-jwt2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Authentication Bypass in Try Mode

Authentication bypass issues exist in hapi-auth-jwt2 version 5.1.1, when try authentication mode is used, request.auth.isAuthenticated will be set to true for unauthenticated users.

How to fix Authentication Bypass in Try Mode?

Upgrade to version 5.1.2 or greater.

<5.1.2