dwyl/hapi-auth-jwt2

dwyl/hapi-auth-jwt2

Releases65
Frequency1 month 3 weeks
Last Release
Stars796
:lock: Secure Hapi.js authentication plugin using JSON Web Tokens (JWT) in Headers, URL or Cookies

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.