Skip to content

Fix prototype pollution for Hapi v16 #230

Closed
@mcollina

Description

@mcollina

As reported in https://hackerone.com/reports/310439, can we have the security fix backported to Hoek 4/Hapi v16 ASAP? Those are vulnerable, still supported, and highly used in production systems.

Snyk is currently flagging the remediation has "upgrade to hapi v17" which is not a good remediation strategy for this type of security fix (and have an extra cost).

Metadata

Metadata

Assignees

Labels

securityIssue with security impact

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions