CVE-2015-9240: High severity KeystoneJS Keystone Node.js vulnerability
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9240?
CVE-2015-9240 is considered a medium severity vulnerability due to its potential to facilitate unauthorized access through incomplete email address matches.
How do I fix CVE-2015-9240?
To fix CVE-2015-9240, upgrade the KeystoneJS module to version 0.3.16 or later.
What is the impact of CVE-2015-9240?
The impact of CVE-2015-9240 is that it may allow attackers to exploit the sign-in functionality using incomplete email addresses, increasing the risk of unauthorized access.
Who is affected by CVE-2015-9240?
CVE-2015-9240 affects users of KeystoneJS version prior to 0.3.16 that rely on the default sign-in functionality.
Is a password still required for CVE-2015-9240 exploitation?
Yes, a correct password is still required to complete the sign-in process despite the incomplete email address vulnerability in CVE-2015-9240.