Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7038 | @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - are vulnerable to their field-level access control not being used. List-level access control is not affected. Field-level access control for fields other than `multiselect` are not affected. Version 2.3.1 contains a fix for this issue. As a workaround, stop using the `multiselect` field. |
Github GHSA |
GHSA-6mhr-52mv-6v6f | Field-level access-control bypass for multiselect field |
Tue, 22 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T17:17:35.770Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39322
Updated: 2024-08-03T12:00:44.121Z
Status : Modified
Published: 2022-10-25T17:15:56.020
Modified: 2024-11-21T07:18:02.117
Link: CVE-2022-39322
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA