GHSA-67g8-c724-8mp3
DDOS attack on graphql endpoints
Quick fix
GHSA-67g8-c724-8mp3 — silverstripe/graphql: upgrade to the fixed version with the command below.
composer require silverstripe/graphql:^4.1.2Details
An attacker could use a specially crafted graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed and particularly large/complex graphql schemas.
If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this will likely further mitigate the risk.
Upgrade to `silverstripe/graphql` 4.2.3 or 4.1.2 or above to remedy the vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.1.1Fixed in: 4.1.2composer require silverstripe/graphql:^4.1.24.2.2Fixed in: 4.2.3composer require silverstripe/graphql:^4.2.3References
- https://github.com/silverstripe/silverstripe-graphql/security/advisories/GHSA-67g8-c724-8mp3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-28104[ADVISORY]
- https://github.com/silverstripe/silverstripe-graphql/pull/526[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/graphql/CVE-2023-28104.yaml[WEB]
- https://github.com/silverstripe/silverstripe-graphql[PACKAGE]
- https://github.com/silverstripe/silverstripe-graphql/releases/tag/4.1.2[WEB]
- https://github.com/silverstripe/silverstripe-graphql/releases/tag/4.2.3[WEB]
- https://www.silverstripe.org/download/security-releases/CVE-2023-28104[WEB]