PT-2023-21229 · Hasura · Hasura Graphql Engine

·

CVE-2023-27588

·

Published

2023-03-14

·

Updated

2023-03-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hasura GraphQL Engine versions prior to 1.3.4 Hasura GraphQL Engine versions prior to 2.55.1 Hasura GraphQL Engine versions prior to 2.20.1 Hasura GraphQL Engine versions prior to 2.21.0-beta1
Description A path traversal vulnerability has been discovered within Hasura GraphQL Engine. The vulnerability affects self-hosted Hasura projects with publicly exposed deployments that are not protected by a WAF or other HTTP protection layer. Projects running on Hasura Cloud are not vulnerable.
Recommendations For versions prior to 1.3.4, upgrade to version 1.3.4 to receive a patch. For versions prior to 2.55.1, upgrade to version 2.55.1 to receive a patch. For versions prior to 2.20.1, upgrade to version 2.20.1 to receive a patch. For versions prior to 2.21.0-beta1, upgrade to version 2.21.0-beta1 to receive a patch.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-27588
GHSA-C9RW-RW2F-MJ4X

Affected Products

Hasura Graphql Engine