A batch loader function in Spring... CVE-2023-34047

- AV AC AU C I A
发布: 2023-09-20
修订: 2023-10-18

A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry.

0%
暂无可用Exp或PoC
当前有2条受影响产品信息