CyberRota Analysis
AI-GeneratedSpring for GraphQL versions 1.2.0 to 2.0.4 are vulnerable to a Denial of Service (DoS) attack due to improper handling of client-supplied values in scrollable queries, which can lead to excessive memory consumption or significant load on the datastore. Organizations using these versions should prioritize patching to mitigate the risk of service disruption caused by maliciously crafted queries. This vulnerability is particularly relevant for developers and system administrators managing applications that utilize Spring for GraphQL.
Original NVD Description
Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.2.0 - 1.3.9
Related CVEs
Other vulnerabilities affecting the same vendor(s)