Cross-site Scripting (XSS) Affecting hapi package, versions <0.16.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDnpm:hapi:20130320
  • published22 Nov 2016
  • disclosed19 Mar 2013
  • creditWyatt Preul

Introduced: 19 Mar 2013

CVE NOT AVAILABLE CWE-79  (opens in a new tab)

How to fix?

Upgrade hapi to version 0.16.0 or higher, although later versions are also susceptible to vulnerabilities. Last known safe version is 11.1.4.

Overview

hapi is an HTTP Server framework. Affected versions of the package are vulnerable to Cross-site Scripting (XSS). They do not handle invalid payloads, allowing attackers craft malicious links or create a third party web page to inject code into the browser. The fix was introduced in version 0.16.0 by parsing the payload and verifying its validity.

Details

<>

CVSS Scores

version 3.1