MEDIUM
GHSA-j3g2-m5jj-6336
Unsafe Merging of CORS Configuration Conflict in hapi
Quick fix
GHSA-j3g2-m5jj-6336 — hapi: upgrade to the fixed version with the command below.
npm install hapi@11.1.4Details
Versions of `hapi` prior to 11.1.4 are affected by a vulnerability that causes route-level CORS configuration to override connection-level or server-level CORS defaults. This may result in a situation where CORS permissions are less restrictive than intended.
## Recommendation
Update hapi to version 11.1.4 or later.
Are you affected?
Enter the version of the package you're using.