Impact
A flaw exists in the GraphQL Directive Handler of birkir prime up to version 0.4.0.beta.0, allowing an attacker to cause an error that leaks sensitive information through detailed error messages. The disclosure can compromise data confidentiality and compromise the integrity of the application. The vulnerability is listed as CWE-200 and CWE-209, but the description does not indicate any authentication or authorization bypass or arbitrary code execution.
Affected Systems
birkir prime, versions up to 0.4.0.beta.0. The affected component is the file /graphql within the GraphQL Directive Handler. Users who have deployed any release of birkir prime before 0.4.0.beta.1 or later are at risk; the scope includes all publicly exposed GraphQL endpoints.
Risk and Exploitability
The CVSS score of 6.9 marks it as a moderate to high severity flaw, and the EPSS score of less than 1% indicates low but non-zero exploitation probability. A publicly available exploit is documented, and the attack can be carried out remotely without prior authentication. The vulnerability is not listed in the CISA KEV catalog, but the publicly available exploitation materials and remote nature raise the risk for systems exposed to the internet.
OpenCVE Enrichment