CVE-2016-10543

CVE-2016-10543

Vendor Hackerone
Product call node module
Weakness CWE-20 · Input validation
Published May 31, 2018
Last update September 17, 2024

CVSS base score

What the vulnerability does

01Description

call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty parameters, which could result in invalid input bypassing the route validation rules.

Key dates

02Disclosure timeline

May 31, 2018 CVE published
September 17, 2024 Record updated