Описание
In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135.
A flaw was found in GraphQL Java. This issue may allow a malicious user to send a crafted GraphQL query that causes stack consumption, causing a denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | graphql-java | Not affected | ||
| Red Hat Integration Camel K 1 | graphql-java | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 7 | graphql-java | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | graphql-java | Not affected | ||
| Red Hat OpenShift Application Runtimes | graphql-java | Will not fix | ||
| Red Hat build of Quarkus 2.13.8.Final | com.graphql-java/graphql-java | Fixed | RHSA-2023:3809 | 29.06.2023 |
| RHINT Service Registry 2.4.3 GA | graphql-java | Fixed | RHSA-2023:3815 | 27.06.2023 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2181977graphql-java: crafted GraphQL query causes stack consumption
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
nvd
почти 3 года назад
In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135.
7.5 High
CVSS3