VDB
Sign up
HIGH8.8

GHSA-q43c-g2g7-6gxj

Cross-Site Request Forgery (CSRF) in keystone

Quick fix

GHSA-q43c-g2g7-6gxj — keystone: upgrade to the fixed version with the command below.

npm install keystone@4.0.0-beta.7

Details

Versions of `keystone` prior to 4.0.0 are vulnerable to Cross-Site Request Forgery (CSRF). The package fails to validate the presence of the `X-CSRF-Token` header, which may allow attackers to carry actions on behalf of other users on all endpoints.

## Recommendation

Update to version 4.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/keystone
Introduced in: 0Fixed in: 4.0.0-beta.7
Fixnpm install keystone@4.0.0-beta.7

References