PT-2022-23922 · Unknown · Graphql-Go

Wgh

·

Published

2022-08-01

·

Updated

2022-08-23

·

CVE-2022-37315

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions graphql-go (aka GraphQL for Go) versions 0.8.0 and earlier
Description The issue concerns infinite recursion in the type definition parser.
Recommendations For versions 0.8.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2022-37315
GHSA-H3QM-JRRF-CGJ3
GO-2022-0942

Affected Products

Graphql-Go