PT-2022-24899 · Unknown · @Keystone-6/Core

Marek R

·

Published

2022-10-18

·

Updated

2022-10-28

·

CVE-2022-39322

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @keystone-6/core versions 2.2.0 through 2.3.0
Description The issue affects users of the multiselect field in @keystone-6/core who have configured field-level access control. The field-level access control is not being used, making the data vulnerable. List-level access control and field-level access control for fields other than multiselect are not affected.
Recommendations For versions 2.2.0 through 2.3.0, upgrade to version 2.3.1 or later, where this issue has been fixed. As a temporary workaround for versions 2.2.0 through 2.3.0, consider stopping the use of the multiselect field until the issue is resolved.

Exploit

Fix

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-39322
GHSA-6MHR-52MV-6V6F

Affected Products

@Keystone-6/Core