Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-26144

Опубликовано: 18 сент. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. Note: It was not proven that this vulnerability can crash the process.

A flaw was found in the graphql package. Affected versions of this package are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This issue may allow an attacker to degrade system performance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift ServerlessgraphqlWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-api-rhel8Will not fix
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Will not fix
Red Hat OpenShift Container Platform 4openshift4/ose-consoleWill not fix
Red Hat OpenShift Data Science (RHODS)rhods/odh-dashboard-rhel8Affected
Red Hat OpenShift Dev Spacesdevspaces/code-rhel8Will not fix
Migration Toolkit for Virtualization 2.5migration-toolkit-virtualization/mtv-console-plugin-rhel9FixedRHBA-2023:607824.10.2023
Red Hat Advanced Cluster Security 4.4advanced-cluster-security/rhacs-main-rhel8FixedRHSA-2024:157028.03.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2239924graphql: Insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries

EPSS

Процентиль: 83%
0.01866
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.

CVSS3: 5.3
nvd
больше 2 лет назад

Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.

CVSS3: 5.3
debian
больше 2 лет назад

Versions of the package graphql from 16.3.0 and before 16.8.1 are vuln ...

CVSS3: 5.3
github
больше 2 лет назад

graphql Uncontrolled Resource Consumption vulnerability

EPSS

Процентиль: 83%
0.01866
Низкий

5.3 Medium

CVSS3