NA

CVE-2023-28867

Published: 27/03/2023 Updated: 03/04/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In GraphQL Java (aka graphql-java) prior to 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135.

Vulnerable Product Search on Vulmon Subscribe to Product

graphql-java graphql-java

graphql-java graphql-java 20.0

Vendor Advisories

Synopsis Important: Service Registry (container images) release and security update [243 GA] Type/Severity Security Advisory: Important Topic An update to the images for Red Hat Integration - Service Registry is now available from the Red Hat Container Catalog The purpose of this text-only errata is to inform you about the security issues ...
Synopsis Moderate: Red Hat build of Quarkus 2138 release and security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat build of Quarkus Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a d ...
DescriptionThe MITRE CVE dictionary describes this issue as: In GraphQL Java (aka graphql-java) before 201, an attacker can send a crafted GraphQL query that causes stack consumption The fixed versions are 201, 194, 184, 175, and 000-2023-03-20T01-49-44-80e3135 ...