Keystone 是一个基于 Node.js 的内容管理系统。在 6.5.3 版本之前, 文件中的 解析器直接将带符号的 参数与 进行比较,这使得远程未认证的 GraphQL 客户端可以提供负数的 值,其绝对值超过配置的上限。这种绕过方式同样适用于关联关系查询,可能导致返回的记录数超出开发者预期,从而可能耗尽服务资源。该问题已在 6.5.3 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| keystonejs | keystone | < 6.5.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| keystonejs | keystone | < 6.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet