CVE-2015-9243
Unsafe Merging of CORS Configuration Conflict in hapi
EPSS 1.0%
描述
Versions of `hapi` prior to 11.1.4 are affected by a vulnerability that causes route-level CORS configuration to override connection-level or server-level CORS defaults. This may result in a situation where CORS permissions are less restrictive than intended. ## Recommendation Update hapi to version 11.1.4 or later.
如何修補 CVE-2015-9243
要修補 CVE-2015-9243,請將受影響套件升級到下列已修補版本。
- npm/hapi—升級至 11.1.4 或更新版本
CVE-2015-9243 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 11.1.4