CVE-2017-16570 describes an application-wide Cross-Site Request Forgery (CSRF) bypass vulnerability affecting KeystoneJS before version 4.0.0-beta.7. The flaw allows attackers to bypass CSRF protection by simply omitting the x-csrf-token header, as the application fails to reject such requests. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk with potential for high impact on confidentiality, integrity, and availability, requiring user interaction but being network exploitable with low attack complexity. While not listed in CISA's KEV catalog and showing no active exploitation or significant community discussion, a public exploit is available on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:keystonejs:keystone:*:beta7:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.