CVE-2015-9236
Incorrect handling of CORS preflight request headers in hapi
EPSS 1.5%
描述
Versions of `hapi` prior to 11.0.0 implement CORS incorrectly, allowing for configurations that at best return inconsistent headers, and at worst allow cross-origin activities that are expected to be forbidden. If the connection has CORS enabled but one route has it off, and the route is not GET, the OPTIONS prefetch request will return the default CORS headers and then the actual request will go through and return no CORS headers. This defeats the purpose of turning CORS on the route. ## Recommendation Update to version 11.0.0 or later.
如何修補 CVE-2015-9236
要修補 CVE-2015-9236,請將受影響套件升級到下列已修補版本。
- —升級至 11.0.0 或更新版本
CVE-2015-9236 正在被利用嗎?
低 — EPSS 為 1.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 11.0.0