CVE Database
/

CVE-2015-9243

Back to search

CVE-2015-9243

Published: May 29, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security restrictions (like origin) would have those restrictions overridden by less restrictive defaults (e.g. origin defaults to all origins `*`).

VendorProductVersions

HackerOne

hapi node module

affected
<11.1.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now