spring-graphql is vulnerable to Information Disclosure
74
High Risk
spring-graphql GraphiQL sends requests to the application's GraphQL endpoints from the victim's browser. A malicious URL can cause those authenticated responses to be leaked to the attacker. This requires GraphiQL to be exposed and the victim to follow a crafted link. The patch stops GraphiQL from disclosing endpoint responses to an untrusted opener.
You are affected if you are using a version that falls within the vulnerable range and the GraphiQL endpoint is enabled and a signed-in user can be induced to open it.
spring-graphql is vulnerable to Information Disclosure in versions 1.0.0 - 2.0.4.
Upgrade the org.springframework.graphql:spring-graphql library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant