Executive brief
Keystone is a Node.js-based CMS and application framework. A cross-site scripting (XSS) vulnerability in Keystone allows attackers to inject malicious scripts into web pages viewed by other users, potentially enabling account takeover, credential theft, or defacement of content.
Technical details
Keystone contains a cross-site scripting vulnerability that was withdrawn as a duplicate of GHSA-7qcx-jmrc-h2rr. The vulnerability affects all versions before 4.0.0. The specific root cause and vulnerable component details are not disclosed in this advisory, but the fix was made available in version 4.0.0. Attack vectors and prerequisites for exploitation are not specified in the available advisory information.
Affected products
- Keystone Keystone before 4.0.0
Timeline
- 2020-08-20: disclosed
- 2020-08-20: patched: Advisory withdrawn as duplicate; fix available in version 4.0.0