spring-graphql is vulnerable to Deserialization of Untrusted Data
81
High Risk
Spring for GraphQL contains an unsafe deserialization vulnerability in the processing of paginated GraphQL queries. Applications that expose paginated (Connection) fields and include certain gadget classes on the classpath may allow attackers to submit specially crafted GraphQL requests that trigger unintended object deserialization behavior. Successful exploitation can lead to remote code execution on the affected system.
You are affected if using a vulnerable version.
spring-graphql is vulnerable to Deserialization of Untrusted Data in versions 2.0.0 - 2.0.3, 1.4.0 - 1.4.5 and 0.0.1 - 1.3.8.
Upgrade the org.springframework.graphql:spring-graphql library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant