CyberRota Analysis
AI-GeneratedThe GraphiQL page in specific versions of Spring for GraphQL is vulnerable due to the loading of JavaScript libraries from a public CDN without Subresource Integrity checks, allowing an attacker to inject malicious code. This could lead to arbitrary code execution in the browser of any user accessing the affected GraphiQL page. Organizations using the specified versions of Spring for GraphQL should prioritize addressing this vulnerability to mitigate potential exploitation risks.
Original NVD Description
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Related CVEs
Other vulnerabilities affecting the same vendor(s)