Api-platform

Core

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 03.04.2025 19:31:46
  • Zuletzt bearbeitet 08.04.2025 14:15:35

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL grant on a property might be cached with different objects. The ApiPlatform\GraphQl\Serializer\ItemNormalizer::isCacheKeySafe() met...

  • EPSS 0.06%
  • Veröffentlicht 03.04.2025 19:20:22
  • Zuletzt bearbeitet 08.04.2025 14:15:35

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.

  • EPSS 0.04%
  • Veröffentlicht 03.04.2025 17:15:30
  • Zuletzt bearbeitet 07.04.2025 14:18:34

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON error response. This vulnerability is fixed in 3.2.5.

  • EPSS 0.13%
  • Veröffentlicht 24.03.2025 15:53:19
  • Zuletzt bearbeitet 27.03.2025 16:45:46

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls bac...

  • EPSS 0.72%
  • Veröffentlicht 28.02.2023 23:15:11
  • Zuletzt bearbeitet 21.11.2024 07:49:45

API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatform\Metadata\ApiProperty` attribute can be disclosed to unauthorized users. The problem aff...

  • EPSS 0.16%
  • Veröffentlicht 04.02.2019 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:17:40

API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the u...