CVE-2017-15879
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
Keystone is vulnerable to CSV injection
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://github.com/keystonejs/keystone/pull/4478
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| npm | keystone | <4.0.0-beta7 | 4.0.0-beta7 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| keystonejs | keystone | {"endIncluding":"4.0.0"} | |
References
- https://github.com/keystonejs/keystone/pull/4478
- https://packetstormsecurity.com/files/144755/KeystoneJS-4.0.0-beta.5-Unauthenticated-CSV-Injection.html
- https://www.exploit-db.com/exploits/43053/
- https://nvd.nist.gov/vuln/detail/CVE-2017-15879
- https://github.com/advisories/GHSA-6494-v9fq-fgq2
- https://www.exploit-db.com/exploits/43053
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.