Vulnerability Description
A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring For Graphql | >= 1.1.0, <= 1.1.5 |
References
- https://spring.io/security/cve-2023-34047Vendor Advisory
- https://spring.io/security/cve-2023-34047Vendor Advisory
FAQ
What is CVE-2023-34047?
CVE-2023-34047 is a vulnerability with a CVSS score of 3.1 (LOW). A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An ap...
How severe is CVE-2023-34047?
CVE-2023-34047 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34047?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring For Graphql.