GHSA-hrgx-7j6v-xj82

Suggest an improvement
Source
https://github.com/advisories/GHSA-hrgx-7j6v-xj82
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-hrgx-7j6v-xj82/GHSA-hrgx-7j6v-xj82.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-hrgx-7j6v-xj82
Aliases
Published
2022-01-12T21:55:40Z
Modified
2023-11-01T04:57:00Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L CVSS Calculator
Summary
Reflected cross-site scripting (XSS) vulnerability
Details

This security advisory relates to a capability for an attacker to exploit a reflected cross-site scripting vulnerability when using the @keystone-6/auth package.

Impact

The vulnerability can impact users of the administration user interface when following an untrusted link to the signin or init page. This is a targeted attack and may present itself in the form of phishing and or chained in conjunction with some other vulnerability.

Vulnerability mitigation

Please upgrade to @keystone-6/auth >= 1.0.2, where this vulnerability has been closed. If you are using @keystone-next/auth, we strongly recommend you upgrade to @keystone-6.

Workarounds

If for some reason you cannot upgrade the dependencies in software, you could alternatively

  • disable the administration user interface, or
  • if using a reverse-proxy, strip query parameters when accessing the administration interface

References

https://owasp.org/www-community/attacks/xss/

Thanks to Shivansh Khari (@Shivansh-Khari) for discovering and reporting this vulnerability

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-01-10T21:45:34Z",
    "nvd_published_at":  "2022-01-12T00:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @keystone-6/auth

Package

Name
@keystone-6/auth
View open source insights on deps.dev
Purl
pkg:npm/%40keystone-6/auth

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-hrgx-7j6v-xj82/GHSA-hrgx-7j6v-xj82.json"

npm / @keystone-next/auth

Package

Name
@keystone-next/auth
View open source insights on deps.dev
Purl
pkg:npm/%40keystone-next/auth

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
37.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-hrgx-7j6v-xj82/GHSA-hrgx-7j6v-xj82.json"