PT-2020-21113 · Datasette · Datasette-Graphql

Published

2020-11-24

·

Updated

2020-11-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions datasette-graphql versions prior to 1.2
Description The issue exposes the schema of private database tables in a Datasette instance when the datasette-graphql plugin is installed and the instance is available on the public internet. However, it does not expose the table contents.
Recommendations For versions prior to 1.2, update to version 1.2 to resolve the issue. As a temporary workaround, consider uninstalling the datasette-graphql plugin or preventing public access to the Datasette instance to minimize the risk of exploitation.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-74HV-QJJQ-H7G5

Affected Products

Datasette-Graphql