API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the user must be authorized. This vulnerability appears to have been fixed in 2.3.6.
{ "nvd_published_at": "2019-02-04T21:29:00Z", "github_reviewed_at": "2019-09-25T12:48:16Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-284" ] }