GHSA-g56x-7j6w-g8r8

    Dashboard / Vulnerabilities / GHSA-g56x-7j6w-g8r8

    GHSA-g56x-7j6w-g8r8

    Published: 18 Dec 2023Last Modified: 16 Feb 2024

    Summary: Grackle has StackOverflowError in GraphQL query processing

    Details: ### Impact Prior to this fix, the GraphQL query parsing was vulnerable to `StackOverflowError`s. The possibility of small queries resulting in stack overflow is a potential denial of service vulnerability. This potentially affects all applications using Grackle which have untrusted users. > [!CAUTION] > **No specific knowledge of an application's GraphQL schema would be required to construct a pathological query.** ### Patches The stack overflow issues have been resolved in the v0.18.0 release of Grackle. ### Workarounds Users could interpose a sanitizing layer in between untrusted input and Grackle query processing.

    Affected packages

    Package

    Name: org.typelevel:grackle-core_2.13

    Purl: pkg:maven/org.typelevel/grackle-core_2.13

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.18.0

    Affected versions

    0.15.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g56x-7j6w-g8r8 | CVE-DB