Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg0ZnYtcHJyYy01Z2dy

Route Validation Bypass in call

Affected versions of call do not validate empty parameters, which may result in a bypass of route validation rules.

Proof of Concept

Routing Scheme:

/api/{param}/{param2}/details

Triggering Request Path:

/api///

Recommendation

Update to version 3.0.2 or later.

Permalink: https://github.com/advisories/GHSA-84fv-prrc-5ggr
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg0ZnYtcHJyYy01Z2dy
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 5 years ago
Updated: over 1 year ago


Identifiers: GHSA-84fv-prrc-5ggr, CVE-2016-10543
References: Repository: https://github.com/hapijs/hapi
Blast Radius: 0.0

Affected Packages

npm:call
Dependent packages: 34
Dependent repositories: 10,841
Downloads: 192,452 last month
Affected Version Ranges: >= 2.0.1, < 3.0.2
Fixed in: 3.0.2
All affected versions: 2.0.1, 2.0.2, 3.0.0, 3.0.1
All unaffected versions: 1.0.0, 2.0.0, 3.0.2, 3.0.3, 3.0.4, 4.0.0, 4.0.1, 4.0.2, 4.1.2, 5.0.0, 5.0.1, 5.0.2, 5.0.3