HIGH7.5
GHSA-h9mq-f6q5-6c8m
GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service
Quick fix
GHSA-h9mq-f6q5-6c8m — com.graphql-java:graphql-java: upgrade to the fixed version with the command below.
# pom.xml: bump <version>19.11</version> for com.graphql-java:graphql-javaDetails
GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.graphql-java:graphql-java
Introduced in:
0Fixed in: 19.11Fix
# pom.xml: bump <version>19.11</version> for com.graphql-java:graphql-javaMaven/com.graphql-java:graphql-java
Introduced in:
20.0Fixed in: 20.9Fix
# pom.xml: bump <version>20.9</version> for com.graphql-java:graphql-javaMaven/com.graphql-java:graphql-java
Introduced in:
21.0Fixed in: 21.5Fix
# pom.xml: bump <version>21.5</version> for com.graphql-java:graphql-javaReferences
- https://nvd.nist.gov/vuln/detail/CVE-2024-40094[ADVISORY]
- https://github.com/graphql-java/graphql-java/pull/3539[WEB]
- https://github.com/graphql-java/graphql-java/commit/16c159111507ef04d7e1839b2c23281d90c42b2b[WEB]
- https://github.com/graphql-java/graphql-java/commit/469caf6ee600ab6709ad5e8a06f371fe2ef3b8dd[WEB]
- https://github.com/graphql-java/graphql-java/commit/97743bc1b5caa2b0bd894dc8e128b47e4d771e4a[WEB]
- https://github.com/graphql-java/graphql-java/commit/fc6f304e66cab18b6d06a80c7009524938939a03[WEB]
- https://github.com/graphql-java/graphql-java/discussions/3641[WEB]
- https://github.com/graphql-java/graphql-java/releases/tag/v19.11[WEB]
- https://github.com/graphql-java/graphql-java/releases/tag/v20.9[WEB]
- https://github.com/graphql-java/graphql-java/releases/tag/v21.5[WEB]