Lucene search

K
nvd[email protected]NVD:CVE-2022-37734
HistorySep 12, 2022 - 2:15 p.m.

CVE-2022-37734

2022-09-1214:15:09
web.nvd.nist.gov
9
vulnerability
graphql-java
denial of service
fixed versions

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

58.9%

graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9.

Affected configurations

Nvd
Node
graphql-java_projectgraphql-javaRange<17.4java
OR
graphql-java_projectgraphql-javaRange18.018.3
VendorProductVersionCPE
graphql-java_projectgraphql-java*cpe:2.3:a:graphql-java_project:graphql-java:*:*:*:*:*:java:*:*
graphql-java_projectgraphql-java*cpe:2.3:a:graphql-java_project:graphql-java:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

58.9%