Authentication Weakness Affecting keystone package, versions <0.3.16


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.89% (55th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDnpm:keystone:20151204
  • published6 Dec 2015
  • disclosed4 Dec 2015
  • creditGreg Meyer

Introduced: 4 Dec 2015

CVE-2015-9240  (opens in a new tab)
CWE-287  (opens in a new tab)

Overview

Invalid email addresses can be mistakenly matched during sign-in. This affects the User record to be fetched from the DB. Correct password for that User is still required to authenticate.

Recommendations

Upgrade to version 0.3.16 or greater.

If a direct dependency update is not possible, use snyk wizard to patch this vulnerability.

CVSS Base Scores

version 3.1