2.0.5
4 years ago
6 days ago
Known vulnerabilities in the org.springframework.graphql:spring-graphql package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.springframework.graphql:spring-graphql is a GraphQL Support for Spring Applications Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the Note: This is only exploitable if the application uses the How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [1.3.0,2.0.5) |
org.springframework.graphql:spring-graphql is a GraphQL Support for Spring Applications Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the pagination support. An attacker can exhaust application memory or place significant, prolonged load on the underlying datastore by forging a malicious query for a Connection field that is backed by a Spring Data repository and exposed through auto-registration support. Note: This is only exploitable if the application exposes a Connection-typed Query field backed by a Spring Data repository through auto-registration support (such as How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [1.2.0,2.0.5) |
org.springframework.graphql:spring-graphql is a GraphQL Support for Spring Applications Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via the Note: This is only exploitable if the How to fix Cross-site Request Forgery (CSRF)? Upgrade | [1.0.0,2.0.5) |
org.springframework.graphql:spring-graphql is a GraphQL Support for Spring Applications Affected versions of this package are vulnerable to Unsafe Dependency Resolution via the Note: This is only exploitable if the How to fix Unsafe Dependency Resolution? Upgrade | [1.0.0,2.0.5) |