GHSA-cqr7-78pj-3g7j

Suggest an improvement
Source
https://github.com/advisories/GHSA-cqr7-78pj-3g7j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-cqr7-78pj-3g7j/GHSA-cqr7-78pj-3g7j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cqr7-78pj-3g7j
Aliases
  • CVE-2014-3742
Published
2017-10-24T18:33:36Z
Modified
2023-11-08T03:57:40Z
Summary
File Descriptor Leak Can Cause DoS Vulnerability in hapi
Details

Versions 2.0.x and 2.1.x of hapi are vulnerable to a denial of service attack via a file descriptor leak.

When triggered repeatedly, this leak will cause the server to run out of file descriptors and the node process to die. The effort required to take down a server depends on the process file descriptor limit. No other side effects or exploits have been identified.

Recommendation

  • Please upgrade to version 2.2.x or above as soon as possible.
Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:32:30Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / hapi

Package

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
2.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-cqr7-78pj-3g7j/GHSA-cqr7-78pj-3g7j.json"