DirectorySecurity Advisories
Sign In
Security Advisories

CGA-gvh2-74x2-p73w

Published

Last updated

https://images.chainguard.dev/security/CGA-gvh2-74x2-p73w
Package

stargate

Latest Update
Fixed
Fixed Version

1.0.85-r1

Aliases
  • CVE-2024-40094
  • GHSA-h9mq-f6q5-6c8m

Severity

7.5

High

CVSS V3

Summary

GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service

Description

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images