We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
This repo is vulnerable to DoS attack(CVE-2022-37734) from com.graphql-java:graphql-java:16.2
com.graphql-java:graphql-java:16.2
Run a check on dependencies list using a plugin like OWASP to list all security vulnerabilities
Dependency check report for vulnerabilities would list CVE-2022-37734
Dependency on com.graphql-java:graphql-java from version before 19.0 makes this repository vulnerable to DoS attack on parsing larger schemas
com.graphql-java:graphql-java
The text was updated successfully, but these errors were encountered:
Mitigate CVE-2022-37734 by updating graphql and jackson dependencies #…
3314b53
…1045 (#1046) Co-authored-by: Upendra Vedullapalli <upendra.rao.vedullapalli@entur.org> Co-authored-by: Bogdan Kobylynskyi <92bogdan@gmail.com>
Thanks @upendrao for working on this. Your fix will be released in 5.7.0 very soon.
Sorry, something went wrong.
@kobylynskyi May I know when can we expect 5.7.0 released?
I am waiting just for one PR to be merged for 5.7.0 and we should be good to go. Thanks.
upendra-vedullapalli
No branches or pull requests
Issue Description
This repo is vulnerable to DoS attack(CVE-2022-37734) from
com.graphql-java:graphql-java:16.2
Steps to Reproduce
Run a check on dependencies list using a plugin like OWASP to list all security vulnerabilities
Expected Result
Dependency check report for vulnerabilities would list CVE-2022-37734
Actual Result
Dependency on
com.graphql-java:graphql-java
from version before 19.0 makes this repository vulnerable to DoS attack on parsing larger schemasYour Environment and Setup
The text was updated successfully, but these errors were encountered: