Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrgx-7j6v-xj82

Опубликовано: 12 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Reflected cross-site scripting (XSS) vulnerability

This security advisory relates to a capability for an attacker to exploit a reflected cross-site scripting vulnerability when using the @keystone-6/auth package.

Impact

The vulnerability can impact users of the administration user interface when following an untrusted link to the signin or init page. This is a targeted attack and may present itself in the form of phishing and or chained in conjunction with some other vulnerability.

Vulnerability mitigation

Please upgrade to @keystone-6/auth >= 1.0.2, where this vulnerability has been closed. If you are using @keystone-next/auth, we strongly recommend you upgrade to @keystone-6.

Workarounds

If for some reason you cannot upgrade the dependencies in software, you could alternatively

  • disable the administration user interface, or
  • if using a reverse-proxy, strip query parameters when accessing the administration interface

References

https://owasp.org/www-community/attacks/xss/

Thanks to Shivansh Khari (@Shivansh-Khari) for discovering and reporting this vulnerability

Пакеты

Наименование

@keystone-6/auth

npm
Затронутые версииВерсия исправления

< 1.0.2

1.0.2

Наименование

@keystone-next/auth

npm
Затронутые версииВерсия исправления

<= 37.0.0

Отсутствует

EPSS

Процентиль: 98%
0.56131
Средний

7.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

EPSS

Процентиль: 98%
0.56131
Средний

7.1 High

CVSS3

Дефекты

CWE-79