vendor:
GraphQL Engine
by:
Dolev Farhi
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: GraphQL Engine
Affected Version From: 1.3.3
Affected Version To: 1.3.3
Patch Exists: YES
Related CWE: N/A
CPE: a:hasura:graphql-engine
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu
2021
Hasura GraphQL 1.3.3 – Remote Code Execution
An attacker can execute arbitrary code on the vulnerable Hasura GraphQL 1.3.3 server by sending a specially crafted request to the /v1/query endpoint. The attacker can use the SET LOCAL statement_timeout and COPY FROM PROGRAM commands to execute arbitrary code on the server.
Mitigation:
Upgrade to the latest version of Hasura GraphQL