{"id":"GHSA-25mx-2mxm-6343","summary":"@keystone-6/core's NODE_ENV defaults to development with esbuild","details":"### Impact\n`@keystone-6/core@3.0.0 || 3.0.1` users that use `NODE_ENV` in their own code (**not dependencies**) to trigger security-sensitive functionality in a production build are vulnerable to `NODE_ENV` being inlined to `\"development\"` for user code.\n\nIf your dependencies use `NODE_ENV` to trigger particular behaviours (optimisations, security or otherwise), they should still respect your environment's configured `NODE_ENV` variable and thereby be unaffected.\n\nIf you do not use `NODE_ENV` in your own code to trigger security-sensitive functionality, **you are not impacted** by this vulnerability.\nAn example of code that would be affected, might be the following:\n\n```typescript\nif (process.env.NODE_ENV !== 'production') {\n  // this code would unintentionally run in your production builds\n}\n```\n\n### Technical Description\nThe problem comes from esbuild defaulting `NODE_ENV` to `\"development\"` when a platform configuration is undefined.\nYou can read about why [`esbuild` has that behaviour in their documentation](https://esbuild.github.io/api/#platform), but the result for Keystone users is that user Typescript was compiled, and had inlined `NODE_ENV` to the constant `\"development\"`. \n\nYour application's dependencies, as found in `node_modules` (including `@keystone-6/core`), are typically not compiled as part of this process, and thus should be unaffected. Therefore any libraries that used `NODE_ENV` to trigger particular behaviours (optimisations, security or otherwise) should still respect your environment's `NODE_ENV`.\nWe have tested this assumption by verifying that `NODE_ENV=production yarn keystone start` still uses secure cookies when using `statelessSessions`.\n\nThereby, the severity of this vulnerability is dependent on what functionality users conditionally triggered, in their own code, depending on the expectation that `NODE_ENV` would be correctly configured in their application. In accordance with Common Vulnerability Scoring System `2.3.3. Assume Vulnerable Configurations`, this security advisory assumes vulnerable configurations and is thus marked as *critical*, but you should evaluate the true security impact for your application to determine a relevant score.\n\n### Patches\nThis vulnerability has been fixed in `@keystone-6/core@3.0.2`, thanks to @mmachatschek in https://github.com/keystonejs/keystone/pull/8031/.\nWe have added regression tests for this vulnerability in https://github.com/keystonejs/keystone/pull/8063.\n\n### Workarounds\nIf you cannot upgrade your `@keystone-6/core` version for any reason, your best alternative is to remove any code that uses `NODE_ENV` in a way that may reasonably impact your application security. \n\n### References\n- https://esbuild.github.io/api/#platform\n- https://github.com/keystonejs/keystone/pull/8031\n- https://github.com/keystonejs/keystone/pull/8063\n\n### For more information\nThanks to [Austin Burdine](https://github.com/acburdine) for reporting this problem as a potential security vulnerability.\n\nIf you have any questions around this security advisory, please don't hesitate to contact us at [security@keystonejs.com](mailto:security@keystonejs.com), or [open an issue on GitHub](https://github.com/keystonejs/keystone/issues/new/choose).\n\nIf you have a security flaw to report for any software in this repository, please see our [SECURITY policy](https://github.com/keystonejs/keystone/blob/main/SECURITY.md).","aliases":["CVE-2022-39382"],"modified":"2023-11-08T04:10:20.410112Z","published":"2022-11-03T18:14:05Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-11-03T18:14:05Z","nvd_published_at":"2022-11-03T14:15:00Z","cwe_ids":["CWE-74"]},"references":[{"type":"WEB","url":"https://github.com/keystonejs/keystone/security/advisories/GHSA-25mx-2mxm-6343"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39382"},{"type":"WEB","url":"https://github.com/keystonejs/keystone/pull/8031"},{"type":"WEB","url":"https://github.com/keystonejs/keystone/pull/8063"},{"type":"PACKAGE","url":"https://github.com/keystonejs/keystone"}],"affected":[{"package":{"name":"@keystone-6/core","ecosystem":"npm","purl":"pkg:npm/%40keystone-6/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-25mx-2mxm-6343/GHSA-25mx-2mxm-6343.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}