Description
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.
Remediation
References
https://nodesecurity.io/advisories/60
Related Vulnerabilities
CVE-2020-26302 Vulnerability in npm package is_js
CVE-2019-10376 Vulnerability in maven package org.jenkins-ci.plugins:jenkinswalldisplay
CVE-2021-33611 Vulnerability in maven package org.webjars.bowergithub.vaadin:vaadin-menu-bar
CVE-2017-12619 Vulnerability in maven package org.apache.zeppelin:zeppelin