Headline
GHSA-p76j-h4m8-hx5c: Pimcore Demo Allows GraphQL Introspection
Introspection is enabled on demo.pimcore.fun
. The demo site has graphql as a feature for users, but allows users to run instropection queries, which presents a potential schema information disclosure vulnerability.
Pimcore Demo Allows GraphQL Introspection
Moderate severity GitHub Reviewed Published Sep 27, 2023 to the GitHub Advisory Database • Updated Sep 27, 2023
Related news
CVE-2023-5192: Disable introspection (#437) · pimcore/demo@a2a7ff3
Excessive Data Query Operations in a Large Data Table in GitHub repository pimcore/demo prior to 10.3.0.