Package
wazuh-dashboard-security-plugin
Component
@hapi/wreck
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable component is @hapi/wreck, whose fix is only available in the 18.x line. The bundled server stack is pinned to the hapi v20 generation, in which @hapi/h2o2 constrains @hapi/wreck to the 17.x range; upgrading to 18.x requires the hapi v21 platform, which the application does not yet support. Pending an upstream release that ships the fix on a compatible line.
Status