PT-2023-22016 · Unknown · Graphql-Java

Dondonz

·

Publicado

2023-03-27

·

Atualizado

2023-09-19

·

CVE-2023-28867

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions graphql-java versions prior to 20.1 graphql-java versions prior to 19.4 graphql-java versions prior to 18.4 graphql-java versions prior to 17.5
Description An attacker can send a crafted GraphQL query that causes stack consumption. The issue affects devices running the vulnerable software, but the estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For versions prior to 20.1, update to version 20.1 or later. For versions prior to 19.4, update to version 19.4 or later. For versions prior to 18.4, update to version 18.4 or later. For versions prior to 17.5, update to version 17.5 or later.

Correção

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28867
GHSA-P4QX-6W5P-4RJ2

Produtos afetados

Graphql-Java