PT-2021-19816 · Unknown · Keystone 5

Dcousens

+1

·

Published

2021-05-24

·

Updated

2021-05-28

·

CVE-2021-32624

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keystone 5 (affected versions not specified)
Description This issue relates to a newly discovered capability in the query infrastructure to directly or indirectly expose the values of private fields, bypassing the configured access control. It is an access control related oracle attack that guides an attacker during their attempt to reveal information they do not have access to. The complexity of completing the attack is limited by some length-dependent behaviors and the fidelity of the exposed information. Under some circumstances, field values or field value meta data can be determined, despite the field or list having read access control configured. If you use private fields or lists, you may be impacted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32624
GHSA-27G8-R9VW-765X

Affected Products

Keystone 5