Description
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.
Remediation
References
https://nodesecurity.io/advisories/60
Related Vulnerabilities
CVE-2017-4974 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2022-24822 Vulnerability in npm package @podium/layout
CVE-2022-3510 Vulnerability in maven package com.google.protobuf:protobuf-javalite
CVE-2021-23337 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash