Record summary

CVE-2022-0087 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE ListBefore @keystone-6/auth@1.0.2affected
GitHub AdvisoryBefore 1.0.2 · Fixed in 1.0.2affected
GitHub AdvisoryThrough 37.0.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMKeystone 6 Login Page - Open Redirect and Cross-Site ScriptingCVSS 6.1

On the login page, there is a "from=" parameter in URL which is vulnerable to open redirect and can be escalated to reflected XSS.

Impact

Attackers can redirect users to malicious websites or inject malicious JavaScript via the from parameter, potentially facilitating phishing attacks or stealing user credentials.

Remediation

Please upgrade to @keystone-6/auth >= 1.0.2, where this vulnerability has been closed. If you are using @keystone-next/auth, we strongly recommend you upgrade to @keystone-6

WeaknessesCWE-79
AuthorsShivanshKhari
Template tagscvecve2022keystoneredirectxssnode.jskeystonejsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:keystonejs:keystone:*:*:*:*:*:node.js:*:*

Source: ProjectDiscovery

References

5