Executive brief
Keystone is a headless CMS and database platform used to build content management systems. Applications using Keystone's multiselect field with field-level access controls allowed unauthorized users to read and modify restricted data, bypassing permission rules intended to limit field visibility. This could expose sensitive data or allow unauthorized modifications to protected records.
Technical details
A field-level access-control bypass exists in the multiselect field implementation of Keystone 6 versions 2.2.0 and 2.3.0. The vulnerability allows attackers on the network to bypass access control rules defined at the field level (create and update permissions) without requiring authentication or user interaction. The flaw affects only multiselect fields with field-level access control; list-level access control and other field types are not impacted. An attacker can read confidential data and modify protected field values. The issue is fixed in version 2.3.1 and later.
Affected products
- Keystone @keystone-6/core 2.2.0 through 2.3.0
Timeline
- 2022-10-18: disclosed: Advisory published
- 2022-10-18: patched: Fix released in version 2.3.1