yar@1.0.0 vulnerabilities

Cookie jar plugin for Hapi

Direct Vulnerabilities

Known vulnerabilities in the yar package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Denial of Service (DoS)

Yar uses an encrypted cookie for session support, during the hapi request/reply flow if this cookie value is invalid (changed by the end-user), a request object variable is not set. In versions prior 2.2.0, the presence of this variable was not validated prior to use, resulting in an unhandled ReferenceError, which in most cases will crash the process.

Source: Node Security Project

How to fix Denial of Service (DoS)?

Update to a version 2.2.0 or greater.

<2.2.0