Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.0.7CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* | ||
>= 1.3.0, < 1.3.9CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* | ||
>= 1.4.0, < 1.4.5.1CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.0.3.1CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.