CVE-2023-34047
Exposure of data and identity to wrong session in Spring for GraphQL
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry.
Una función de cargador por lotes en Spring para las versiones GraphQL 1.1.0 - 1.1.5 y 1.2.0 - 1.2.2 puede estar expuesta al contexto GraphQL con valores, incluidos valores de contexto de seguridad, de una sesión diferente. Una aplicación es vulnerable si proporciona una instancia de DataLoaderOptions al registrar funciones del cargador por lotes a través de DefaultBatchLoaderRegistry.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-05-25 CVE Reserved
- 2023-09-20 CVE Published
- 2024-09-24 CVE Updated
- 2024-09-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://spring.io/security/cve-2023-34047 | 2023-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Spring For Graphql Search vendor "Vmware" for product "Spring For Graphql" | >= 1.1.0 <= 1.1.5 Search vendor "Vmware" for product "Spring For Graphql" and version " >= 1.1.0 <= 1.1.5" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Spring For Graphql Search vendor "Vmware" for product "Spring For Graphql" | >= 1.2.0 <= 1.2.2 Search vendor "Vmware" for product "Spring For Graphql" and version " >= 1.2.0 <= 1.2.2" | - |
Affected
|