{"id":"GHSA-6mhr-52mv-6v6f","summary":"Field-level access-control bypass for multiselect field","details":"#### Impact\n\n`@keystone-6/core@2.2.0 || 2.3.0` users who are using the `multiselect` field, and provided field-level access control - are vulnerable to their field-level access control not being used.\n\nList-level access control is **NOT** affected.\n\nField-level access control for fields other than `multiselect` are **NOT** affected.\n\nExample, **you are vulnerable if** you are using field-level access control on a `multiselect` like the following:\n```ts\nconst yourList = list({\n  access: {\n    // this is list-level access control, this is NOT impacted\n  },\n  fields: {\n    yourFieldName: multiselect({\n      // this is field-level access control, for multiselect fields\n      //   this is vulnerable\n      access: {\n        create: ({ session }) =\u003e session?.data.isAdmin,\n        update: ({ session }) =\u003e session?.data.isAdmin,\n      },\n      options: [\n        { value: 'apples', label: 'Apples' },\n        { value: 'oranges', label: 'Oranges' },\n      ],\n      // ...\n    }),\n    // ...\n  },\n  // ...\n});\n```\n\n#### Mitigation\nPlease upgrade to `@keystone-6/core \u003e= 2.3.1`, where this vulnerability has been closed.\n\n#### Workarounds\nIf for some reason you cannot upgrade your dependencies, you should stop using the `multiselect` field.\n\n#### Credits\nThanks to [Marek R](https://github.com/marekryb) for reporting and submitting the pull request to fix this problem.\n\nIf you have any questions around this security advisory, please don't hesitate to contact us at [security@keystonejs.com](mailto:security@keystonejs.com), or [open an issue on GitHub](https://github.com/keystonejs/keystone/issues/new/choose).\n\nIf you have a security flaw to report for any software in this repository, please see our [SECURITY policy](https://github.com/keystonejs/keystone/blob/main/SECURITY.md).","aliases":["CVE-2022-39322"],"modified":"2023-11-08T04:10:18.824607Z","published":"2022-10-18T17:12:46Z","database_specific":{"nvd_published_at":"2022-10-25T17:15:00Z","cwe_ids":["CWE-285","CWE-863"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-10-18T17:12:46Z"},"references":[{"type":"WEB","url":"https://github.com/keystonejs/keystone/security/advisories/GHSA-6mhr-52mv-6v6f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39322"},{"type":"WEB","url":"https://github.com/keystonejs/keystone/commit/65c6ee3deef23605fc72b80230908696a7a65e7c"},{"type":"PACKAGE","url":"https://github.com/keystonejs/keystone"}],"affected":[{"package":{"name":"@keystone-6/core","ecosystem":"npm","purl":"pkg:npm/%40keystone-6/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.2.0"},{"fixed":"2.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-6mhr-52mv-6v6f/GHSA-6mhr-52mv-6v6f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}