The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.0.7CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* | ||
>= 1.3.0, < 1.3.9CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* | ||
>= 1.4.0, < 1.4.5.1CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.0.3.1CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.