Elide is a narrowly scoped data-access and query-authorization framework, with vulnerabilities clustering around its core product and centered on access-control and data-exposure issues such as improper authorization, external directory accessibility, and SQL-injection flaws in query handling. These weakness patterns reflect the structural risks inherent to a system mediating authentication and data-layer access; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elide over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24827HIGH Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the following together: Elide Aggregation Data Store for Analytic | Apr 11, 2022 | 8.1 | 26 | NO | NO |
CVE-2020-5289MEDIUM In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field i | Mar 30, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elide.
Media articles that mention a CVE ID that affects a product developed by Elide — matched by CVE ID, not by vendor name.