graphiti is vulnerable to Information Disclosure
75
High Risk
Graphiti resources expose a stats[group_by] parameter that accepts a client supplied attribute name. Unlike filter, sort, and fields, the grouping key is passed to the ActiveRecord adapter's grouping without checking it against the resource's readable attributes. A caller can group on any column of the backing table, including undeclared columns and attributes declared non-readable, and read back their distinct values such as password reset tokens. The fix validates the group key against the resource's readable policy and rejects unknown or unreadable attributes.
You are affected if you are using a version that falls within the vulnerable range and you expose a resource whose adapter supports stats[group_by] grouping.
graphiti is vulnerable to Information Disclosure in versions 1.3.9 - 1.13.4 and 2.0.0 - 2.0.1.
Upgrade the graphiti library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.