CVE-2015-9240
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.
Affected products
HackerOne · keystone node moduleReferences
https://nodesecurity.io/advisories/60