CVE-2022-37734
12.09.2022, 14:15
graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9.Enginsight
Vendor | Product | Version |
---|---|---|
graphql-java_project | graphql-java | 𝑥 < 17.4 |
graphql-java_project | graphql-java | 18.0 ≤ 𝑥 < 18.3 |
𝑥
= Vulnerable software versions
References