VDB
Sign up
HIGH7.5

GHSA-67g8-c724-8mp3

DDOS attack on graphql endpoints

Quick fix

GHSA-67g8-c724-8mp3 — silverstripe/graphql: upgrade to the fixed version with the command below.

composer require silverstripe/graphql:^4.1.2

Details

An attacker could use a specially crafted graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed and particularly large/complex graphql schemas.

If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this will likely further mitigate the risk.

Upgrade to `silverstripe/graphql` 4.2.3 or 4.1.2 or above to remedy the vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/graphql
Introduced in: 4.1.1Fixed in: 4.1.2
Fixcomposer require silverstripe/graphql:^4.1.2
Packagist/silverstripe/graphql
Introduced in: 4.2.2Fixed in: 4.2.3
Fixcomposer require silverstripe/graphql:^4.2.3

References