graphql-java vulnerable to Denial of Service via GraphQL query that consumes CPU resources
High severity
GitHub Reviewed
Published
Sep 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
< 17.4
>= 18.0, < 18.3
Patched versions
17.4
18.3
Description
Published by the National Vulnerability Database
Sep 12, 2022
Published to the GitHub Advisory Database
Sep 13, 2022
Reviewed
Sep 16, 2022
Last updated
Jan 27, 2023
graphql-java before 19.0, 18.3, and 17.4 is vulnerable to Denial of Service. An attacker send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0, 18.3, and 17.4.
References