CVE-2014-7193: Medium severity hapi vulnerability
The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtain sensitive information, and potentially obtain the ability to spoof requests to non-CORS routes, via a crafted web site that is visited by an application consumer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7193?
CVE-2014-7193 is considered a high severity vulnerability due to its potential for sensitive information disclosure and request spoofing.
How do I fix CVE-2014-7193?
To fix CVE-2014-7193, you should upgrade the Crumb plugin for Node.js to version 3.0.0 or later.
What type of attacks can be performed by exploiting CVE-2014-7193?
Exploiting CVE-2014-7193 can allow attackers to obtain sensitive information and spoof requests to non-CORS routes.
Which versions of Crumb are affected by CVE-2014-7193?
CVE-2014-7193 affects Crumb plugin versions before 3.0.0.
What is the impact of CVE-2014-7193 on Node.js applications?
The impact of CVE-2014-7193 on Node.js applications includes the potential exposure of sensitive data and unauthorized request spoofing.