PT-2022-24942 · Unknown · @Keystone-6/Core

·

CVE-2022-39382

·

Published

2022-11-03

·

Updated

2022-11-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @keystone-6/core versions 3.0.0 through 3.0.1
Description The issue arises when NODE ENV is inlined to "development" for user code, regardless of the environment variables. This affects users who use NODE ENV to trigger security-sensitive functionality in their production builds. The application's dependencies, found in node modules, are typically not compiled and should be unaffected. The vulnerability has been fixed in @keystone-6/core@3.0.2.
Recommendations For @keystone-6/core versions 3.0.0 through 3.0.1, update to @keystone-6/core@3.0.2 to resolve the issue. As a temporary workaround, consider removing any code that uses NODE ENV in a way that may reasonably impact application security.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39382
GHSA-25MX-2MXM-6343

Affected Products

@Keystone-6/Core