CVE-2023-28867
Summary
| CVE | CVE-2023-28867 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-27 01:15:00 UTC |
| Updated | 2023-04-03 14:01:00 UTC |
| Description | In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release 17.5 · graphql-java/graphql-java · GitHub |
MISC |
github.com |
|
| Release 18.4 · graphql-java/graphql-java · GitHub |
MISC |
github.com |
|
| Release 19.4 · graphql-java/graphql-java · GitHub |
MISC |
github.com |
|
| Preventing stack overflow exceptions via limiting the depth of the parser rules by bbakerman · Pull Request #3112 · graphql-java/graphql-java · GitHub |
MISC |
github.com |
|
| Release 20.1 · graphql-java/graphql-java · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378729 IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6999681)
- 378942 IBM Spectrum Protect Operations Center Denial of Service (DoS) Vulnerability (7034039)