Description
When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.
Remediation
References
https://github.com/dwyl/hapi-auth-jwt2/issues/111
https://github.com/dwyl/hapi-auth-jwt2/pull/112
https://nodesecurity.io/advisories/81
Related Vulnerabilities
CVE-2022-45389 Vulnerability in maven package com.cloudbees.jenkins.plugins:xpdev
CVE-2022-36076 Vulnerability in npm package nodebb
CVE-2021-46708 Vulnerability in npm package swagger-ui
CVE-2020-36048 Vulnerability in npm package engine.io
CVE-2019-12399 Vulnerability in maven package org.apache.kafka:kafka