PT-2020-21113 · Datasette · Datasette-Graphql
Published
2020-11-24
·
Updated
2020-11-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
datasette-graphql versions prior to 1.2
Description
The issue exposes the schema of private database tables in a Datasette instance when the
datasette-graphql plugin is installed and the instance is available on the public internet. However, it does not expose the table contents.Recommendations
For versions prior to 1.2, update to version 1.2 to resolve the issue.
As a temporary workaround, consider uninstalling the
datasette-graphql plugin or preventing public access to the Datasette instance to minimize the risk of exploitation.Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datasette-Graphql