vendor:
GraphQL Engine
by:
Dolev Farhi
8.8
CVSS
HIGH
Service Side Request Forgery (SSRF)
918
CWE
Product Name: GraphQL Engine
Affected Version From: 1.3.3
Affected Version To: 1.3.3
Patch Exists: NO
Related CWE: N/A
CPE: a:hasura:graphql-engine
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu
2021
Hasura GraphQL 1.3.3 – Service Side Request Forgery (SSRF)
Hasura GraphQL 1.3.3 is vulnerable to Service Side Request Forgery (SSRF). An attacker can exploit this vulnerability to send requests to internal services that are not accessible from the external network. This can be used to gain access to sensitive information or to perform other malicious activities.
Mitigation:
The best way to mitigate SSRF is to validate the user input and ensure that it is not pointing to any internal services.