Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Unauthenticated path traversal vulnerability in Hasura GraphQL Engine
Vulnerability Description
Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4, 2.55.1, 2.20.1, and 2.21.0-beta1. Projects running on Hasura Cloud were not vulnerable. Self-hosted Hasura Projects with deployments that are publicly exposed and not protected by a WAF or other HTTP protection layer should be upgraded to version 1.3.4, 2.55.1, 2.20.1, or 2.21.0-beta1 to receive a patch.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
路径遍历:’dir/../../filename’
Vulnerability Title
Hasura GraphQL Engine 路径遍历漏洞
Vulnerability Description
Hasura GraphQL Engine是Hasura开源的一个非常快速的 GraphQL 服务器。 Hasura GraphQL Engine 存在安全漏洞,该漏洞源于存在路径遍历漏洞。
CVSS Information
N/A
Vulnerability Type
N/A