QID 982318
QID 982318: Nodejs (npm) Security Update for keystone (GHSA-q43c-g2g7-6gxj)
Versions of `keystone` prior to 4.0.0 are vulnerable to Cross-Site Request Forgery (CSRF). The package fails to validate the presence of the `X-CSRF-Token` header, which may allow attackers to carry actions on behalf of other users on all endpoints.
## Recommendation
Update to version 4.0.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q43c-g2g7-6gxj for updates pertaining to this vulnerability.
Vendor References
- GHSA-q43c-g2g7-6gxj -
github.com/advisories/GHSA-q43c-g2g7-6gxj
CVEs related to QID 982318
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q43c-g2g7-6gxj | keystone |
|