Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-40094

Опубликовано: 30 июл. 2024
Источник: redhat
CVSS3: 7.5

Описание

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

A vulnerability was found in GraphQL Java, affecting versions prior to 21.5. This flaw allows an attacker to perform a denial of service (DoS) attack via introspection queries. The issue arises due to the improper handling of ExecutableNormalizedFields (ENFs), which are not adequately considered during the introspection query process. This issue could lead to resource exhaustion and service disruption under certain conditions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apicurio Registry 2graphql-javaNot affected
Red Hat Fuse 7graphql-javaOut of support scope
Red Hat Integration Camel K 1graphql-javaOut of support scope
Red Hat JBoss Enterprise Application Platform 7graphql-javaOut of support scope
Red Hat JBoss Enterprise Application Platform 8graphql-javaNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packgraphql-javaNot affected
Cryostat 3 on RHEL 8cryostat-tech-preview/cryostat-db-rhel8FixedRHSA-2024:832922.10.2024
Cryostat 3 on RHEL 8cryostat-tech-preview/cryostat-grafana-dashboard-rhel8FixedRHSA-2024:832922.10.2024
Cryostat 3 on RHEL 8cryostat-tech-preview/cryostat-operator-bundleFixedRHSA-2024:832922.10.2024
Cryostat 3 on RHEL 8cryostat-tech-preview/cryostat-ose-oauth-proxy-rhel8FixedRHSA-2024:832922.10.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2301456graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

CVSS3: 7.5
github
около 2 лет назад

GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service

7.5 High

CVSS3