GHSA-974j-wjxx-wggj
Dashboard / Vulnerabilities / GHSA-974j-wjxx-wggj
Summary: Incorrect Access Control vulnerability in api-platform/core
Details: API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the user must be authorized. This vulnerability appears to have been fixed in 2.3.6.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-1000011, https://github.com/api-platform/core/issues/2364, https://github.com/api-platform/core/pull/2441, https://github.com/FriendsOfPHP/security-advisories/blob/master/api-platform/core/CVE-2019-1000011.yaml
Affected packages
Package
Name: api-platform/core
Purl: pkg:composer/api-platform/core
Affected ranges
Type: ECOSYSTEM
Events:
