PT-2024-34133 · Graphql+1 · Graphql+1

Maksymilian Kubiak

+2

·

Published

2024-10-22

·

Updated

2025-01-15

·

CVE-2024-50312

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GraphQL (affected versions not specified)
Description: A vulnerability was found in GraphQL due to improper access controls on the graphql introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the attack surface, as it can facilitate the discovery of flaws or errors specific to the application's GraphQL implementation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the graphql introspection query to minimize the risk of exploitation. Apply available patches immediately to mitigate risks.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-50312
GO-2024-3211
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Graphql
Suse