CVE-2024-50312

Source
https://cve.org/CVERecord?id=CVE-2024-50312
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-50312.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-50312
Aliases
Downstream
Related
Published
2024-10-22T13:24:12.165Z
Modified
2026-07-15T01:48:55.325617137Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Graphql: information disclosure via graphql introspection in openshift
Details

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the attack surface, as it can facilitate the discovery of flaws or errors specific to the application's GraphQL implementation.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50312.json",
    "cna_assigner": "redhat"
}
References

Affected packages

Git / github.com/openshift/console

Affected ranges

Type
GIT
Repo
https://github.com/openshift/console
Events
Database specific
{
    "cpe": "cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "4.0"
        },
        {
            "last_affected": "4.0"
        }
    ]
}

Affected versions

4.*
4.0
v4.*
v4.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-50312.json"