PT-2024-34133 · Graphql+1 · Graphql+1
Maksymilian Kubiak
+2
·
Published
2024-10-22
·
Updated
2025-01-15
·
CVE-2024-50312
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
GraphQL (affected versions not specified)
Description:
A vulnerability was found in GraphQL due to improper access controls on the
graphql introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the attack surface, as it can facilitate the discovery of flaws or errors specific to the application's GraphQL implementation.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
graphql introspection query to minimize the risk of exploitation. Apply available patches immediately to mitigate risks.Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Graphql
Suse