← Back

CVE-2023-28104

nvd nist
Published: Mar 16, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly affects websites with particularly large/complex graphql schemas. Users should upgrade to `silverstripe/graphql` 4.2.3 or 4.1.2 to remedy the vulnerability.

Affected (2)

1 product
Graphql
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Silverstripe
Version 4.1.1
Version 4.2.2

References (8)

Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
PatchRelease Notes
Source: security-advisories@github.com
PatchRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
PatchRelease Notes

Timeline

No history available yet.