Lucene search

K
cveMitreCVE-2023-28867
HistoryMar 27, 2023 - 1:15 a.m.

CVE-2023-28867

2023-03-2701:15:07
CWE-770
mitre
web.nvd.nist.gov
66
cve-2023-28867
graphql
java
security
vulnerability
nvd
stack consumption

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

49.5%

In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135.

Affected configurations

Nvd
Node
graphql-javagraphql-javaRange<17.5
OR
graphql-javagraphql-javaRange18.018.4
OR
graphql-javagraphql-javaRange19.019.4
OR
graphql-javagraphql-javaMatch20.0
VendorProductVersionCPE
graphql-javagraphql-java*cpe:2.3:a:graphql-java:graphql-java:*:*:*:*:*:*:*:*
graphql-javagraphql-java20.0cpe:2.3:a:graphql-java:graphql-java:20.0:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

49.5%