Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
GraphQl securityAfterResolver not called
Vulnerability Description
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls back to `security`, the impact is there only when there's only a security after resolver and none inside security. Version 3.3.15 contains a patch for the issue.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
API Platform Core 安全漏洞
Vulnerability Description
API Platform Core是API Platform开源的一个 API Platform 的服务器组件。 API Platform Core存在安全漏洞,该漏洞源于存在安全检查问题。
CVSS Information
N/A
Vulnerability Type
N/A