CyberRota Analysis
AI-GeneratedThe GraphiQL page in Spring for GraphQL versions 1.0.0 through 2.0.4 is vulnerable to an attack where an attacker can craft a malicious URL that, when accessed by a victim, may lead to the leakage of sensitive information from the victim's browser to the attacker's site. This vulnerability poses a significant risk to applications utilizing these versions of Spring for GraphQL, particularly those handling confidential data. Organizations using affected versions should prioritize remediation to mitigate potential data exposure risks.
Original NVD Description
The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Related CVEs
Other vulnerabilities affecting the same vendor(s)