CVE-2014-3742
File Descriptor Leak Can Cause DoS Vulnerability in hapi
EPSS 0.73%
Description
Versions 2.0.x and 2.1.x of hapi are vulnerable to a denial of service attack via a file descriptor leak. When triggered repeatedly, this leak will cause the server to run out of file descriptors and the node process to die. The effort required to take down a server depends on the process file descriptor limit. No other side effects or exploits have been identified. ## Recommendation - Please upgrade to version 2.2.x or above as soon as possible.
How to fix CVE-2014-3742
To remediate CVE-2014-3742, upgrade the affected package to a fixed version below.
- —upgrade to 2.2.0 or later
Is CVE-2014-3742 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 2.0.0, < 2.2.0