Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-37734

Опубликовано: 12 сент. 2022
Источник: redhat
CVSS3: 7.5

Описание

graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9.

A flaw was found in GraphQL Java. This flaw allows an attacker to use a malicious query in GraphQL to cause a denial of service due to inefficient lexer input validation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Quarkusgraphql-javaFix deferred
Red Hat Fuse 7graphql-javaNot affected
Red Hat Integration Camel K 1graphql-javaFix deferred
Red Hat JBoss Enterprise Application Platform 7graphql-javaNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packgraphql-javaNot affected
Red Hat build of Eclipse Vert.x 4.3.3graphql-javaFixedRHSA-2022:675705.10.2022
Red Hat build of Quarkus 2.13.5FixedRHSA-2022:902314.12.2022
RHINT Service Registry 2.3.0 GAgraphql-javaFixedRHSA-2022:683506.10.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2126809graphql-java: DoS by malicious query

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9.

CVSS3: 7.5
github
больше 3 лет назад

graphql-java vulnerable to Denial of Service via GraphQL query that consumes CPU resources

7.5 High

CVSS3