Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a HTTP 500 error back to the sender, hapi node module before 11.1.3 will continue to hold the socket open until timed out (default node timeout is 2 minutes).
The product does not properly control the allocation and maintenance of a limited resource.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://github.com/jfhbrook/node-ecstatic/pull/179 | issue tracking exploit third party advisory |
https://github.com/hapijs/hapi/commit/aab2496e930dce5ee1ab28eecec94e0e45f03580 | third party advisory patch |
https://nodesecurity.io/advisories/63 | third party advisory |