QID 994862
Date Published: 2023-08-17
QID 994862: NodeJs (Npm) Security Update for @keystone-6/core (GHSA-9cvc-v7wm-992c)
When ui.isAccessAllowed is undefined, the adminMeta GraphQL query is publicly accessible, that is to say, no session is required for the query.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9cvc-v7wm-992c for updates and patch information.
Vendor References
- GHSA-9cvc-v7wm-992c -
github.com/advisories/GHSA-9cvc-v7wm-992c
CVEs related to QID 994862
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9cvc-v7wm-992c | @keystone-6/core |
|