Junglewise Threat Intelligence

CVE-2021-32624: KeystoneJS Keystone 5 access control bypass in query infrastructure

CVE-2021-32624 · Severity: low · CVSS 3.1 · Published 2021-05-27

Technologies: KeystoneJS Keystone 5. Vendors: KeystoneJS, npm.

Executive brief

Keystone 5, a popular open-source platform for building Node.js applications, contains a vulnerability that could allow unauthorized users to view private data. By exploiting a flaw in how the system handles database queries, an attacker can bypass security controls to reveal sensitive information that should be hidden. This could lead to the exposure of private user details or internal business data, potentially damaging customer trust and violating privacy regulations.

Technical details

Keystone 5 is vulnerable to an access control oracle attack within its query infrastructure (CWE-200). The flaw allows an authenticated attacker with low privileges to directly or indirectly determine the values of private fields or metadata, even when 'read' access controls are explicitly configured. The attack complexity is considered high as it relies on observing length-dependent behaviors and the fidelity of exposed information to reconstruct sensitive data. At the time of disclosure, no official patches or workarounds were available for the affected versions (up to 19.3.2).

Affected products

  • KeystoneJS Keystone 5 (@keystonejs/keystone) <= 19.3.2

Timeline

  • 2021-05-24: advisory: Initial advisory published by KeystoneJS and NVD
  • 2021-05-27: disclosed: GHSA published

References