GHSA-jqxr-vjvv-899m

Suggest an improvement
Source
https://github.com/advisories/GHSA-jqxr-vjvv-899m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-jqxr-vjvv-899m/GHSA-jqxr-vjvv-899m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jqxr-vjvv-899m
Aliases
Published
2023-06-14T14:54:06Z
Modified
2023-11-08T04:12:45Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N CVSS Calculator
Summary
@keystone-6/auth Open Redirect vulnerability
Details

Summary

There is an open redirect in the @keystone-6/auth package, where the redirect leading / filter can be bypassed.

Impact

Users may be redirected to domains other than the relative host, thereby it might be used by attackers to re-direct users to an unexpected location.

Mitigations

  • Don't use the @keystone-6/auth package

References

Similar Vulnerability Reports

Credits

Thanks to morioka12 for reporting this problem.

If you have any questions around this security advisory, please don't hesitate to contact us at security@keystonejs.com, or open an issue on GitHub.

If you have a security flaw to report for any software in this repository, please see our SECURITY policy.

Database specific
{
    "cwe_ids":  [
        "CWE-601"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-06-14T14:54:06Z",
    "nvd_published_at":  "2023-06-13T17:15:14Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / @keystone-6/auth

Package

Name
@keystone-6/auth
View open source insights on deps.dev
Purl
pkg:npm/%40keystone-6/auth

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-jqxr-vjvv-899m/GHSA-jqxr-vjvv-899m.json"