Remote Code Execution (RCE)
Discription

image
graphql-ruby is vulnerable to Remote Code Execution (RCE). The vulnerability is due to unsafe schema loading due to the ability to execute arbitrary code when processing a malicious schema definition using GraphQL::Schema.from_introspection or GraphQL::Schema::Loader.load from an untrusted…Read More

Back to Main

Subscribe for the latest news: