yar@2.1.0 vulnerabilities
Cookie jar plugin for Hapi
-
latest version
9.1.0
-
latest non vulnerable version
-
first published
11 years ago
-
latest version published
5 years ago
-
licenses detected
- >=0.0.1 <4.0.0
Direct Vulnerabilities
Known vulnerabilities in the yar package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
Yar uses an encrypted cookie for session support, during the hapi request/reply flow if this cookie value is invalid (changed by the end-user), a request object variable is not set. In versions prior 2.2.0, the presence of this variable was not validated prior to use, resulting in an unhandled ReferenceError, which in most cases will crash the process. Source: Node Security Project How to fix Denial of Service (DoS)? Update to a version 2.2.0 or greater. |
<2.2.0
|