Описание
SilverStripe GraphQL Server permission checker not inherited by query subclass.
Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-28661
- https://github.com/silverstripe/silverstripe-graphql/pull/407/commits/16961459f681f7b32145296189dfdbcc7715e6ed
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/graphql/CVE-2021-28661.yaml
- https://github.com/silverstripe/silverstripe-graphql/releases
- https://github.com/silverstripe/silverstripe-graphql/releases/tag/3.5.2
- https://www.silverstripe.org/download/security-releases/CVE-2021-28661
Пакеты
Наименование
silverstripe/graphql
composer
Затронутые версииВерсия исправления
>= 3.0.0, < 3.5.2
3.5.2
Связанные уязвимости
CVSS3: 4.3
nvd
больше 4 лет назад
Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.