VDB
Sign up
HIGH7.5

GHSA-h9mq-f6q5-6c8m

GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service

Quick fix

GHSA-h9mq-f6q5-6c8m — com.graphql-java:graphql-java: upgrade to the fixed version with the command below.

# pom.xml: bump <version>19.11</version> for com.graphql-java:graphql-java

Details

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.graphql-java:graphql-java
Introduced in: 0Fixed in: 19.11
Fix# pom.xml: bump <version>19.11</version> for com.graphql-java:graphql-java
Maven/com.graphql-java:graphql-java
Introduced in: 20.0Fixed in: 20.9
Fix# pom.xml: bump <version>20.9</version> for com.graphql-java:graphql-java
Maven/com.graphql-java:graphql-java
Introduced in: 21.0Fixed in: 21.5
Fix# pom.xml: bump <version>21.5</version> for com.graphql-java:graphql-java

References