Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9mq-f6q5-6c8m

Опубликовано: 30 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

Пакеты

Наименование

com.graphql-java:graphql-java

maven
Затронутые версииВерсия исправления

< 19.11

19.11

Наименование

com.graphql-java:graphql-java

maven
Затронутые версииВерсия исправления

>= 20.0, < 20.9

20.9

Наименование

com.graphql-java:graphql-java

maven
Затронутые версииВерсия исправления

>= 21.0, < 21.5

21.5

EPSS

Процентиль: 95%
0.1753
Средний

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
redhat
больше 1 года назад

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

CVSS3: 5.3
nvd
больше 1 года назад

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

EPSS

Процентиль: 95%
0.1753
Средний

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770