Записи hapijs
7 опубликованных записей вендора hapijs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption3
- CWE-284 Improper Access Control2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-471 Modification of Assumed-Immutable Data (MAID)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2018-3728Эксплойта нет | hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' hapijs · hoek · CWE-471 | Высокая8,8 | — | 4,2 % | 30 мар. 2018 г. |
32Наблюдать | CVE-2020-36604Эксплойта нет | hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.hapijs · hoek · CWE-1321 | Высокая8,1 | — | 1,2 % | 23 сент. 2022 г. |
31Наблюдать | CVE-2015-9241Эксплойта нет | Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised.hapijs · hapi · CWE-400 | Высокая7,5 | — | 2,1 % | 29 мая 2018 г. |
30Наблюдать | CVE-2017-16013Эксплойта нет | hapi is a web and services application framework.hapijs · hapi · CWE-400 | Высокая7,5 | — | 1,6 % | 4 июн. 2018 г. |
24Наблюдать | CVE-2017-16025Эксплойта нет | Nes is a websocket extension library for hapi.hapijs · nes · CWE-400 | Средняя5,9 | — | 1,9 % | 4 июн. 2018 г. |
23Наблюдать | CVE-2015-9243Эксплойта нет | When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher levehapijs · hapi · CWE-284 | Средняя5,9 | — | 1,0 % | 29 мая 2018 г. |
21Наблюдать | CVE-2015-9236Эксплойта нет | Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at whapijs · hapi · CWE-284 | Средняя5,3 | — | 1,5 % | 31 мая 2018 г. |
- CVE-2018-372836Наблюдать
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge'
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %hapijs · hoek30 мар. 2018 г.
- CVE-2020-3660432Наблюдать
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %hapijs · hoek23 сент. 2022 г.
- CVE-2015-924131Наблюдать
Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %hapijs · hapi29 мая 2018 г.
- CVE-2017-1601330Наблюдать
hapi is a web and services application framework.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %hapijs · hapi4 июн. 2018 г.
- CVE-2017-1602524Наблюдать
Nes is a websocket extension library for hapi.
СредняяCVSS 5,9Эксплойта нетEPSS 2 %hapijs · nes4 июн. 2018 г.
- CVE-2015-924323Наблюдать
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher leve
СредняяCVSS 5,9Эксплойта нетEPSS 1 %hapijs · hapi29 мая 2018 г.
- CVE-2015-923621Наблюдать
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at w
СредняяCVSS 5,3Эксплойта нетEPSS 2 %hapijs · hapi31 мая 2018 г.