Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-40094

Опубликовано: 30 июл. 2024
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

A vulnerability was found in GraphQL Java, affecting versions prior to 21.5. This flaw allows an attacker to perform a denial of service (DoS) attack via introspection queries. The issue arises due to the improper handling of ExecutableNormalizedFields (ENFs), which are not adequately considered during the introspection query process. This issue could lead to resource exhaustion and service disruption under certain conditions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apicurio Registry 2com.graphql-java/graphql-javaNot affected
Red Hat Fuse 7com.graphql-java/graphql-javaOut of support scope
Red Hat Integration Camel K 1com.graphql-java/graphql-javaOut of support scope
Red Hat JBoss Enterprise Application Platform 7com.graphql-java/graphql-javaOut of support scope
Red Hat JBoss Enterprise Application Platform 8com.graphql-java/graphql-javaNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packcom.graphql-java/graphql-javaNot affected
Cryostat 3 on RHEL 8cryostat-tech-preview/cryostat-db-rhel8FixedRHSA-2024:832922.10.2024
Cryostat 3 on RHEL 8cryostat-tech-preview/cryostat-grafana-dashboard-rhel8FixedRHSA-2024:832922.10.2024
Cryostat 3 on RHEL 8cryostat-tech-preview/cryostat-operator-bundleFixedRHSA-2024:832922.10.2024
Cryostat 3 on RHEL 8cryostat-tech-preview/cryostat-ose-oauth-proxy-rhel8FixedRHSA-2024:832922.10.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2301456graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java

EPSS

Процентиль: 95%
0.1753
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

CVSS3: 7.5
github
больше 1 года назад

GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service

EPSS

Процентиль: 95%
0.1753
Средний

7.5 High

CVSS3