GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.
History

Wed, 23 Oct 2024 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat cryostat
CPEs cpe:/a:redhat:cryostat:3::el8
Vendors & Products Redhat
Redhat cryostat

Fri, 27 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Title graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-07-30T00:00:00

Updated: 2024-08-02T04:33:11.692Z

Reserved: 2024-07-05T00:00:00

Link: CVE-2024-40094

cve-icon Vulnrichment

Updated: 2024-07-30T14:42:11.908Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-30T07:15:01.840

Modified: 2024-07-30T13:32:45.943

Link: CVE-2024-40094

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-07-30T00:00:00Z

Links: CVE-2024-40094 - Bugzilla