logo

GHSA-9xgp-hfw7-73rq keystone

Package

Manager: npm
Name: keystone
Vulnerable Version: <0

Severity

Level: Medium

CVSS v3.1: N/A

CVSS v4.0: N/A

EPSS: N/A pctlN/A

Details

Authentication Weakness in keystone There is an authentication weakness vulnerability in keystone before version 0.3.16. Due to a bug in the the default sign in functionality, incomplete email addresses could be matched. A correct password is still required to complete sign in.

Metadata

Created: 2020-08-19T21:30:04Z
Modified: 2020-08-19T21:30:04Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-9xgp-hfw7-73rq/GHSA-9xgp-hfw7-73rq.json
CWE IDs: []
Alternative ID: N/A
Finding: N/A
Auto approve: 0