@strapi/plugin-graphql is vulnerable to Private Data Structure Returned From A Public Method
32
Low Risk
Affected versions of this package expose attributes tagged as private within the GraphQL input and filter schema definitions. This vulnerability can lead to unintended data exposure, allowing clients to query or filter sensitive fields that should remain hidden. As a result, attackers or unauthorized users may gain access to confidential information, potentially compromising the security and privacy of the application’s data.
You are affected if you are using a version which is within vulnerability ranges
@strapi/plugin-graphql is vulnerable to Private Data Structure Returned From A Public Method in versions 4.0.0 - 5.4.1.
Upgrade the @strapi/plugin-graphql library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant