Vulnerability record · CVE-2023-34247 · published 13 June 2023
CVE-2023-34247: Keystonejs keystone open redirect vulnerability
Keystonejs · Keystone
Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package versions 7.0.0 and prior, where the redirect leading `/` filter can be bypassed. Users may be redirected to domains other than the relative host, thereby it might be used by attackers to re-direct users to an unexpected location. To mitigate this issue, one may apply a patch from pull request 8626 or avoid using the `@keystone-6/auth` package.
Description
Keystone is a content management system for Node.JS. There is an open redirect in the `@keystone-6/auth` package versions 7.0.0 and prior, where the redirect leading `/` filter can be bypassed. Users may be redirected to domains other than the relative host, thereby it might be used by attackers to re-direct users to an unexpected location. To mitigate this issue, one may apply a patch from pull request 8626 or avoid using the `@keystone-6/auth` package.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/keystonejs/keystone/pull/8626 | PatchThird Party Advisory |
| https://github.com/keystonejs/keystone/security/advisories/GHSA-jqxr-vjvv-899m | Third Party Advisory |
| https://github.com/keystonejs/keystone/pull/8626 | PatchThird Party Advisory |
| https://github.com/keystonejs/keystone/security/advisories/GHSA-jqxr-vjvv-899m | Third Party Advisory |
Track CVE-2023-34247 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34247), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.