silverstripe/graphql
Packagist7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting silverstripe/graphqlpage 1 of 1
- CVE-2019-12437HIGHCVSS 8.8EG 8.8fixed in 2.0.5 or 3.1.2, by version range2020-02-19
vulnerable: 3.1.0, 3.1.1
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
- CVE-2020-26136MEDIUMCVSS 6.5EG 6.5fixed in 3.5.0 or 4.0.0-alpha2, by version range2021-06-08
vulnerable: 4.0.0-alpha1
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
- CVE-2020-6165MEDIUMCVSS 5.3EG 5.3fixed in 3.2.42020-07-15
vulnerable: 3.2.0, 3.2.1, 3.2.2, 3.2.3
SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms. The automatic permission-checking mechanism in the silverstripe/graphql module does not p…
- CVE-2021-28661MEDIUMCVSS 4.3EG 4.3fixed in 3.5.22021-10-07
vulnerable: 3.0.0 ... 3.5.1 (31 versions)
Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.
- CVE-2023-28104HIGHCVSS 7.5EG 7.5fixed in 4.1.2 or 4.2.3, by version range2023-03-16
vulnerable: 4.2.2
`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly e…
- CVE-2023-40180HIGHCVSS 7.5EG 7.5fixed in 3.8.2, 4.1.3, 4.2.5, 4.3.4 or 5.0.3, by version range2023-10-16
vulnerable: 5.0.0, 5.0.1, 5.0.2
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly af…
- CVE-2023-44401MEDIUMCVSS 5.3EG 5.3fixed in 4.3.7 or 5.1.3, by version range2024-01-23
vulnerable: 5.0.0 ... 5.1.2 (9 versions)
The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results wh…
Check whether silverstripe/graphql is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for silverstripe/graphql CVEs against the assets you own.
Book a Demo →