Exposure of data and identity to wrong session in Spring for GraphQL

LOW | SEPTEMBER 19, 2023 | CVE-2023-34047

Description

A batch loader function in Spring for GraphQL may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry.

Affected Spring Products and Versions

Spring for GraphQL:

  • 1.2.0 - 1.2.2
  • 1.1.5 and earlier

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.
Fix versionAvailability
1.2.3OSS
1.1.6OSS

No further mitigation steps are necessary.

Credit

The issue was reported by Jack Rowland.

History

  • 2023-09-19: Initial vulnerability report published.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all