Skip to content

Hawk dependency causes security risk #2874

@lightkraken

Description

@lightkraken

I recently ran a Node Security scan on a project that uses Request and found a security issue related to the version of Hawk (and subsequently Hoek) that Request is using.

request@2.83.0 > hawk@6.0.2 > hoek@4.2.0

https://nodesecurity.io/advisories/566
https://hackerone.com/reports/310439

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions