{"id":"GHSA-9xgp-hfw7-73rq","summary":"Authentication Weakness in keystone","details":"There is an authentication weakness vulnerability in keystone before version 0.3.16.  Due to a bug in the the default sign in functionality, incomplete email addresses could be matched. A correct password is still required to complete sign in.","modified":"2020-08-19T21:30:04Z","published":"2020-08-19T21:30:04Z","withdrawn":"2020-08-19T21:30:04Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2019-05-29T19:21:31Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/keystonejs/keystone/issues/1085"}],"affected":[{"package":{"name":"keystone","ecosystem":"npm","purl":"pkg:npm/keystone"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-9xgp-hfw7-73rq/GHSA-9xgp-hfw7-73rq.json"}}],"schema_version":"1.9.0"}