CVE-2023-28867

CVSS V2 None CVSS V3 None
Description
In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135.
Overview
  • CVE ID
  • CVE-2023-28867
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-27T01:15:07
  • Last Modified Date
  • 2023-04-03T14:01:07
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:graphql-java:graphql-java:*:*:*:*:*:*:*:* 1 OR 17.5
cpe:2.3:a:graphql-java:graphql-java:*:*:*:*:*:*:*:* 1 OR 18.0 18.4
cpe:2.3:a:graphql-java:graphql-java:*:*:*:*:*:*:*:* 1 OR 19.0 19.4
cpe:2.3:a:graphql-java:graphql-java:20.0:*:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 03:29:13 Added to TrackCVE
2023-04-17 03:29:15 Weakness Enumeration new