GraphQL Java vulnerable to stack consumption
High severity
GitHub Reviewed
Published
Mar 27, 2023
to the GitHub Advisory Database
•
Updated Apr 3, 2023
Package
Affected versions
< 0.0.0-2023-03-20T01-49-44-80e3135
>= 1.2, < 17.5
>= 18.0, < 18.4
>= 19.0, < 19.4
= 20.0
Patched versions
0.0.0-2023-03-20T01-49-44-80e3135
17.5
18.4
19.4
20.1
Description
Published by the National Vulnerability Database
Mar 27, 2023
Published to the GitHub Advisory Database
Mar 27, 2023
Reviewed
Mar 27, 2023
Last updated
Apr 3, 2023
In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135.
References