hapijs kayıtları
hapijs üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption3
- CWE-284 Improper Access Control2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-471 Modification of Assumed-Immutable Data (MAID)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2018-3728İstismar yok | hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' hapijs · hoek · CWE-471 | Yüksek8,8 | — | %4,2 | 30 Mar 2018 |
32İzleyin | CVE-2020-36604İstismar yok | hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.hapijs · hoek · CWE-1321 | Yüksek8,1 | — | %1,2 | 23 Eyl 2022 |
31İzleyin | CVE-2015-9241İstismar yok | Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised.hapijs · hapi · CWE-400 | Yüksek7,5 | — | %2,1 | 29 May 2018 |
30İzleyin | CVE-2017-16013İstismar yok | hapi is a web and services application framework.hapijs · hapi · CWE-400 | Yüksek7,5 | — | %1,6 | 4 Haz 2018 |
24İzleyin | CVE-2017-16025İstismar yok | Nes is a websocket extension library for hapi.hapijs · nes · CWE-400 | Orta5,9 | — | %1,9 | 4 Haz 2018 |
23İzleyin | CVE-2015-9243İstismar yok | When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher levehapijs · hapi · CWE-284 | Orta5,9 | — | %1,0 | 29 May 2018 |
21İzleyin | CVE-2015-9236İstismar yok | Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at whapijs · hapi · CWE-284 | Orta5,3 | — | %1,5 | 31 May 2018 |
- CVE-2018-372836İzleyin
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge'
YüksekCVSS 8,8İstismar yokEPSS %4hapijs · hoek30 Mar 2018
- CVE-2020-3660432İzleyin
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.
YüksekCVSS 8,1İstismar yokEPSS %1hapijs · hoek23 Eyl 2022
- CVE-2015-924131İzleyin
Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised.
YüksekCVSS 7,5İstismar yokEPSS %2hapijs · hapi29 May 2018
- CVE-2017-1601330İzleyin
hapi is a web and services application framework.
YüksekCVSS 7,5İstismar yokEPSS %2hapijs · hapi4 Haz 2018
- CVE-2017-1602524İzleyin
Nes is a websocket extension library for hapi.
OrtaCVSS 5,9İstismar yokEPSS %2hapijs · nes4 Haz 2018
- CVE-2015-924323İzleyin
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher leve
OrtaCVSS 5,9İstismar yokEPSS %1hapijs · hapi29 May 2018
- CVE-2015-923621İzleyin
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at w
OrtaCVSS 5,3İstismar yokEPSS %2hapijs · hapi31 May 2018