Executive brief
@keystone-6/auth is an authentication library used by Keystone CMS applications. The package contains an open redirect vulnerability that allows attackers to bypass validation filters and redirect users to arbitrary external domains, potentially enabling phishing attacks or malware distribution.
Technical details
The @keystone-6/auth package contains an open redirect vulnerability (CWE-601) where a redirect leading slash filter can be bypassed, allowing user-controlled input to specify links to external sites without proper validation. The vulnerability requires adjacent network access, low privileges, and user interaction to exploit. An authenticated attacker can craft a malicious redirect URL that bypasses the validation logic, causing users to be redirected to untrusted domains. The vulnerability was patched in version 7.0.1 and all earlier versions including 7.0.0 remain vulnerable.
Affected products
- Keystone @keystone-6/auth <7.0.1
Timeline
- 2023-06-14: disclosed
- 2023-06-14: patched: Fixed in version 7.0.1