Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreA batch loader function in Spring for GraphQL may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry.
Spring for GraphQL:
| Fix version | Availability |
|---|---|
| 1.2.3 | OSS |
| 1.1.6 | OSS |
No further mitigation steps are necessary.
The issue was reported by Jack Rowland.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy