spring-graphql is vulnerable to Deserialization of Untrusted Data
81
High Risk
spring-graphql pagination support can deserialize untrusted Connection arguments with Jackson 2.x. If gadget classes are on the classpath, a crafted GraphQL request can execute unintended logic during deserialization. This requires exposed Connection fields plus Jackson 2.x. The patch restricts types that pagination cursors and arguments may deserialize into.
You are affected if you are using a version that falls within the vulnerable range and paginated GraphQL Connection fields are deserialized with Jackson 2.x.
spring-graphql is vulnerable to Deserialization of Untrusted Data in versions 2.0.0 - 2.0.4.
Upgrade the org.springframework.graphql:spring-graphql library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant