GHSA-cqmq-8755-7xvh
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
Quick fix
GHSA-cqmq-8755-7xvh — @keystone-6/core: upgrade to the fixed version with the command below.
npm install @keystone-6/core@6.5.3 Details
# Summary The value of `graphql.maxTake` can be bypassed by providing a negative input. This can be used to exceed the developer's intended `graphql.maxTake` value, allowing queries to return results in excess of the `graphql.maxTake` value set.
# Impact This affects any project relying on `graphql.maxTake` to bound the number of items returned per query.
# Patches This issue has been patched in `@keystone-6/core` version `6.5.3`.
If you cannot patch, you can workaround this by restricting `take` input values in your GraphQL queries to the bounded value, or by blocking negative values.
# Credit This issue was found by [Haxset's](https://haxset.com) Security Scanner and validated by their team.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/keystonejs/keystone/security/advisories/GHSA-cqmq-8755-7xvh [WEB]
- https://github.com/keystonejs/keystone/pull/9859 [WEB]
- https://github.com/keystonejs/keystone/commit/9fb88b246950ce4de754a43fe6416f20403577b1 [WEB]
- https://github.com/keystonejs/keystone [PACKAGE]
- https://github.com/keystonejs/keystone/releases/tag/@keystone-6/core@6.5.3 [WEB]