GHSA-27g8-r9vw-765x

Suggest an improvement
Source
https://github.com/advisories/GHSA-27g8-r9vw-765x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-27g8-r9vw-765x/GHSA-27g8-r9vw-765x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-27g8-r9vw-765x
Aliases
Related
Published
2021-05-27T18:39:03Z
Modified
2026-03-13T22:15:22.017688Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Private Field data leak
Details

This security advisory relates to a newly discovered capability in our query infrastructure to directly or indirectly expose the values of private fields, bypassing the configured access control.

This is an access control related oracle attack in that the attack method guides an attacker during their attempt to reveal information they do not have access to. The complexity of completing the attack is limited by some length-dependent behaviors and the fidelity of the exposed information.

Impact

Under some circumstances, field values or field value meta data can be determined, despite the field or list having read access control configured. If you use private fields or lists, you may be impacted.

Patches

None, at this time

Workarounds

None, at this time

References

None

For more information

For the protection of the community and private deployments, we think that the best course of action will be to not disclose further details on any open GitHub issues related to this advisory until a hot-fix or work-around has been deployed or published.

If needed, you can email us at keystone@thinkmill.com.au

Database specific
{
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2021-05-25T20:20:03Z",
    "nvd_published_at": "2021-05-24T17:15:00Z"
}
References

Affected packages

npm / @keystonejs/keystone

Package

Name
@keystonejs/keystone
View open source insights on deps.dev
Purl
pkg:npm/%40keystonejs/keystone

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
19.3.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-27g8-r9vw-765x/GHSA-27g8-r9vw-765x.json"