PT-2021-17888 · Silverstripe · Silverstripe Graphql Server

Lukereative

·

Published

2021-10-07

·

Updated

2024-03-06

·

CVE-2021-28661

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SilverStripe GraphQL Server versions 3.x through 3.4.1
Description: The issue concerns a permission checker not being inherited by a query subclass in the SilverStripe GraphQL Server.
Recommendations: For versions 3.x through 3.4.1, update to a version where this issue is resolved, as the current version does not properly inherit permission checkers for query subclasses. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-SILVERSTRIPE-2021-28661
CVE-2021-28661
GHSA-R7RH-G777-G5GX

Affected Products

Silverstripe Graphql Server