CVE-2021-47715
EUVD-2021-3474422.12.2025, 22:15
Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL definitions to potentially access internal network resources.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hasura | graphql_engine | 1.3.3 |
𝑥
= Vulnerable software versions