Intel

AIKIDO-2024-10333

api-platform/core is vulnerable to Missing Authorization

Missing Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 11, 2024

80

High Risk

This Affects:

phpapi-platform/core
4.0.0 - 4.0.2
Fixed in 4.0.3
Are you affected? Scan for Free

TL;DR

Affected versions of the package lack proper authorization on the GraphQL endpoints. This vulnerability allows unauthorized users to access or modify sensitive data through the GraphQL interface, potentially exposing or manipulating information they should not have access to.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

api-platform/core is vulnerable to Missing Authorization in versions 4.0.0 - 4.0.2.

How to fix this

Upgrade the api-platform/core library to the patch version.