silverstripe/graphql
Packagist7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting silverstripe/graphqlpage 1 of 1
- CVE-2019-12437HIGHCVSS 8.8EG 8.8✓ Fixed in 3.1.22020-02-19
vulnerable: 3.1.0, 3.1.1
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
- CVE-2020-26136MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.0.0-alpha22021-06-08
vulnerable: 4.0.0-alpha1
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
- CVE-2020-6165MEDIUMCVSS 5.3EG 5.3✓ Fixed in 3.2.42020-07-15
vulnerable: 3.2.0, 3.2.1, 3.2.2, 3.2.3
SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms. The automatic permission-checking mechanism in the silverstripe/graphql module does not p…
- CVE-2021-28661MEDIUMCVSS 4.3EG 4.3✓ Fixed in 3.5.22021-10-07
vulnerable: 3.0.0 ... 3.5.1 (31 versions)
Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.
- CVE-2023-28104HIGHCVSS 7.5EG 7.5✓ Fixed in 4.2.32023-03-16
vulnerable: 4.2.2
`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly e…
- CVE-2023-40180HIGHCVSS 7.5EG 7.5✓ Fixed in 5.0.32023-10-16
vulnerable: 5.0.0, 5.0.1, 5.0.2
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly af…
- CVE-2023-44401MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.1.32024-01-23
vulnerable: 5.0.0 ... 5.1.2 (9 versions)
The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results wh…
Check whether silverstripe/graphql is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for silverstripe/graphql CVEs against the assets you own.
Start Free Scan →