VDB
Sign up
CRITICAL9.0

GHSA-q92j-grw3-h492

graphql allows remote code execution when loading a crafted GraphQL schema

Quick fix

GHSA-q92j-grw3-h492 — graphql: upgrade to the fixed version with the command below.

bundle update graphql

Details

# Summary

Loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any system which loads a schema by JSON from an untrusted source is vulnerable, including those that use [GraphQL::Client](https://github.com/github-community-projects/graphql-client) to load external schemas via GraphQL introspection.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/graphql
Introduced in: 2.4.0Fixed in: 2.4.13
Fixbundle update graphql
RubyGems/graphql
Introduced in: 2.3.0Fixed in: 2.3.21
Fixbundle update graphql
RubyGems/graphql
Introduced in: 2.2.0Fixed in: 2.2.17
Fixbundle update graphql
RubyGems/graphql
Introduced in: 2.1.0Fixed in: 2.1.15
Fixbundle update graphql
RubyGems/graphql
Introduced in: 2.0.0Fixed in: 2.0.32
Fixbundle update graphql
RubyGems/graphql
Introduced in: 1.13.0Fixed in: 1.13.24
Fixbundle update graphql
RubyGems/graphql
Introduced in: 1.12.0Fixed in: 1.12.25
Fixbundle update graphql
RubyGems/graphql
Introduced in: 1.11.5Fixed in: 1.11.11
Fixbundle update graphql

References