PT-2021-19816 · Unknown · Keystone 5
Dcousens
+1
·
Published
2021-05-24
·
Updated
2021-05-28
·
CVE-2021-32624
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Keystone 5 (affected versions not specified)
Description
This issue relates to a newly discovered capability in the query infrastructure to directly or indirectly expose the values of private fields, bypassing the configured access control. It is an access control related oracle attack that guides an attacker during their attempt to reveal information they do not have access to. The complexity of completing the attack is limited by some length-dependent behaviors and the fidelity of the exposed information. Under some circumstances, field values or field value meta data can be determined, despite the field or list having
read access control configured. If you use private fields or lists, you may be impacted.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keystone 5