GHSA-r7rh-g777-g5gx
Dashboard / Vulnerabilities / GHSA-r7rh-g777-g5gx
GHSA-r7rh-g777-g5gx
Summary: SilverStripe GraphQL Server permission checker not inherited by query subclass.
Details: Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-28661, https://github.com/silverstripe/silverstripe-graphql/pull/407/commits/16961459f681f7b32145296189dfdbcc7715e6ed, https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/graphql/CVE-2021-28661.yaml, https://github.com/silverstripe/silverstripe-graphql, https://github.com/silverstripe/silverstripe-graphql/releases, https://github.com/silverstripe/silverstripe-graphql/releases/tag/3.5.2, https://www.silverstripe.org/download/security-releases/CVE-2021-28661
Affected packages
Package
Name: silverstripe/graphql
Purl: pkg:composer/silverstripe/graphql
Affected ranges
Type: ECOSYSTEM
Events:
