CVE-2021-28661: Incorrect Authorization
(updated )
Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.
References
- github.com/advisories/GHSA-r7rh-g777-g5gx
- github.com/silverstripe/silverstripe-graphql/pull/407/commits/16961459f681f7b32145296189dfdbcc7715e6ed
- github.com/silverstripe/silverstripe-graphql/releases
- github.com/silverstripe/silverstripe-graphql/releases/tag/3.5.2
- nvd.nist.gov/vuln/detail/CVE-2021-28661
- www.silverstripe.org/download/security-releases/CVE-2021-28661
Detect and mitigate CVE-2021-28661 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →