spring-graphql is vulnerable to Inclusion of Functionality from Untrusted Control Sphere
75
High Risk
spring-graphql GraphiQL loads JavaScript from a public CDN without Subresource Integrity. If the CDN or the path to it is compromised, the browser executes attacker script in the application origin. That script can read non-HttpOnly cookies and issue authenticated GraphQL operations. The patch stops loading GraphiQL assets from an untrusted CDN without integrity protection.
You are affected if you are using a version that falls within the vulnerable range and the GraphiQL endpoint is enabled and reachable.
spring-graphql is vulnerable to Inclusion of Functionality from Untrusted Control Sphere in versions 1.0.0 - 2.0.4.
Upgrade the org.springframework.graphql:spring-graphql library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant