Impact
The vulnerability occurs in the GraphiQL interface bundled with Spring for GraphQL. A crafted URL can cause a victim’s browser to send GraphQL requests that may expose confidential data to an attacker’s domain. This results in information disclosure and compromises the confidentiality of data accessed by the GraphQL endpoints.
Affected Systems
The issue affects Spring for GraphQL. Supported products are: Spring:Spring for GraphQL. Affected releases include 2.0.0‑2.0.4, 1.4.0‑1.4.6, 1.1.0‑1.3.9, and 1.0.0‑1.0.7. If your application uses any of these versions, it is vulnerable.
Risk and Exploitability
The CVSS score is 7.5 and the EPSS score is less than 1%, indicating a low yet non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. The attack vector is likely an attacker issuing a malicious URL that a victim clicks, causing the victim’s browser to send GraphQL requests that could leak confidential data. Since the leak depends on the victim accessing the crafted URL, the risk is limited to those exposed to the link, but the potential loss of confidential information remains significant.
OpenCVE Enrichment