CVE-2023-34047

CVSS v3.1 4.3 (Medium)
43% Progress
EPSS 0.07 % (31th)
0.07% Progress
Affected Products 1
Advisories 1

A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry.

Weaknesses
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
VMware
Published Date
2023-09-20 10:15:14
(12 months ago)
Updated Date
2023-10-18 18:04:30
(11 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Vmware Spring for Graphql from 1.1.0 version and 1.1.5 and prior versions cpe:2.3:a:vmware:spring_for_graphql >= 1.1.0 <= 1.1.5
  Vmware Spring for Graphql from 1.2.0 version and 1.2.2 and prior versions cpe:2.3:a:vmware:spring_for_graphql >= 1.2.0 <= 1.2.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...