{"id":"GHSA-hrgx-7j6v-xj82","summary":"Reflected cross-site scripting (XSS) vulnerability","details":"This security advisory relates to a capability for an attacker to exploit a reflected cross-site scripting vulnerability when using the `@keystone-6/auth` package.\n\n#### Impact\nThe vulnerability can impact users of the administration user interface when following an untrusted link to the `signin` or `init` page.\nThis is a targeted attack and may present itself in the form of phishing and or chained in conjunction with some other vulnerability.\n\n## Vulnerability mitigation\nPlease upgrade to `@keystone-6/auth \u003e= 1.0.2`, where this vulnerability has been closed.\nIf you are using `@keystone-next/auth`,  we **strongly** recommend you upgrade to `@keystone-6`.\n\n### Workarounds\nIf for some reason you cannot upgrade the dependencies in software, you could alternatively\n\n- disable the administration user interface, or \n- if using a reverse-proxy, strip query parameters when accessing the administration interface\n\n### References\nhttps://owasp.org/www-community/attacks/xss/\n\nThanks to Shivansh Khari (@Shivansh-Khari) for discovering and reporting this vulnerability","aliases":["CVE-2022-0087"],"modified":"2023-11-01T04:57:00.962257Z","published":"2022-01-12T21:55:40Z","database_specific":{"github_reviewed_at":"2022-01-10T21:45:34Z","nvd_published_at":"2022-01-12T00:15:00Z","cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/keystonejs/keystone/security/advisories/GHSA-hrgx-7j6v-xj82"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0087"},{"type":"WEB","url":"https://github.com/keystonejs/keystone/commit/96bf833a23b1a0a5d365cf394467a943cc481b38"},{"type":"PACKAGE","url":"https://github.com/keystonejs/keystone"},{"type":"WEB","url":"https://huntr.dev/bounties/c9d7374f-2cb9-4bac-9c90-a965942f413e"}],"affected":[{"package":{"name":"@keystone-6/auth","ecosystem":"npm","purl":"pkg:npm/%40keystone-6/auth"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-hrgx-7j6v-xj82/GHSA-hrgx-7j6v-xj82.json"}},{"package":{"name":"@keystone-next/auth","ecosystem":"npm","purl":"pkg:npm/%40keystone-next/auth"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"37.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-hrgx-7j6v-xj82/GHSA-hrgx-7j6v-xj82.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"}]}