Vulnerability Description
The VTEX [email protected] GraphQL API module does not properly restrict unauthorized access to private configuration data. ([email protected] is unaffected by this issue.)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vtex | Apps-Graphql | 2.x |
Related Weaknesses (CWE)
References
- https://developers.vtex.com/updates/release-notes/deprecation-of-apps-graphql%40
- https://developers.vtex.com/updates/release-notes/deprecation-of-apps-graphql%40
FAQ
What is CVE-2023-28877?
CVE-2023-28877 is a vulnerability with a CVSS score of 7.5 (HIGH). The VTEX [email protected] GraphQL API module does not properly restrict unauthorized access to private configuration data. ([email protected] is unaffected by this issue.)
How severe is CVE-2023-28877?
CVE-2023-28877 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28877?
Check the references section above for vendor advisories and patch information. Affected products include: Vtex Apps-Graphql.