VDB
Sign up
—

DRUPAL-CONTRIB-2021-013

Details

This module lets you craft and expose a GraphQL web service API.

The module does not sufficiently protect arbitrary exception and error messages thereby exposing an information disclosure vulnerability.

This vulnerability is mitigated by the fact that a GraphQL server must be enabled and a data producer be configured that throws exceptions with confidential error messages that must not be exposed over the GraphQL API.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/graphql
Introduced in: 4.0.0

No fixed version published yet for drupal/graphql. Pin to a known-safe version or switch to an alternative.

References