spring-graphql is vulnerable to Missing Origin Validation in WebSockets
81
High Risk
Spring for GraphQL applications that enable the GraphQL WebSocket transport and rely on cookie-based session authentication may be vulnerable to Cross-Site WebSocket Hijacking when WebSocket Origin validation is not enforced. An attacker can trick an authenticated user into visiting a malicious webpage, allowing arbitrary GraphQL operations to be executed through the victim's authenticated session and potentially leading to unauthorized access or modification of application data.
You are affected if using a vulnerable version.
spring-graphql is vulnerable to Missing Origin Validation in WebSockets in versions 2.0.0 - 2.0.3, 1.4.0 - 1.4.5, 1.1.0 - 1.3.8 and 0.0.1 - 1.0.6.
Upgrade the org.springframework.graphql:spring-graphql library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant