Lucene search

K
cve[email protected]CVE-2022-31173
HistoryAug 01, 2022 - 7:15 p.m.

CVE-2022-31173

2022-08-0119:15:08
CWE-400
CWE-674
web.nvd.nist.gov
436
4
juniper
graphql
rust
vulnerability
uncontrolled recursion
cve-2022-31173

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

57.2%

Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. This issue has been addressed in version 0.15.10. Users are advised to upgrade. Users unable to upgrade should limit the recursion depth manually.

Affected configurations

Vulners
NVD
Node
graphql-rustjuniperRange<0.15.10

CNA Affected

[
  {
    "product": "juniper",
    "vendor": "graphql-rust",
    "versions": [
      {
        "status": "affected",
        "version": "< 0.15.10"
      }
    ]
  }
]

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

57.2%

Related for CVE-2022-31173