CVE-2017-16570

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
06/11/2017
Last modified:
20/04/2025

Description

KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an x-csrf-token header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:keystonejs:keystone:*:beta7:*:*:*:*:*:* 4.0.0 (excluding)