PT-2023-21229 · Hasura · Hasura Graphql Engine

40826D

·

Published

2023-03-14

·

Updated

2023-03-21

·

CVE-2023-27588

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hasura GraphQL Engine versions prior to 1.3.4 Hasura GraphQL Engine versions prior to 2.55.1 Hasura GraphQL Engine versions prior to 2.20.1 Hasura GraphQL Engine versions prior to 2.21.0-beta1
Description A path traversal vulnerability has been discovered within Hasura GraphQL Engine. The vulnerability affects self-hosted Hasura projects with publicly exposed deployments that are not protected by a WAF or other HTTP protection layer. Projects running on Hasura Cloud are not vulnerable.
Recommendations For versions prior to 1.3.4, upgrade to version 1.3.4 to receive a patch. For versions prior to 2.55.1, upgrade to version 2.55.1 to receive a patch. For versions prior to 2.20.1, upgrade to version 2.20.1 to receive a patch. For versions prior to 2.21.0-beta1, upgrade to version 2.21.0-beta1 to receive a patch.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-27588
GHSA-C9RW-RW2F-MJ4X

Affected Products

Hasura Graphql Engine