Vulnerabilities > CVE-2015-9240 - Credentials Management vulnerability in Keystonejs Keystone

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
keystonejs
CWE-255

Summary

Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.

Vulnerable Configurations

Part Description Count
Application
Keystonejs
150

Common Weakness Enumeration (CWE)