CVE-2024-47082

CVSS 3.1 Score 8 of 10 (high)

Details

Published Sep 25, 2024
Updated: Oct 1, 2024
CWE ID 352

Summary

CVE-2024-47082 is a vulnerability affecting the Strawberry GraphQL library before version 0.243.0. By default, these integrations enabled multipart file uploads, making them susceptible to Cross-Site Request Forgery (CSRF) attacks. The Django HTTP view integration had an additional exemption for Django's built-in CSRF protection, further increasing the risk. As a result, all Strawberry integrations were vulnerable to CSRF attacks without the explicit enabling of security mechanisms. Version 0.243.0 is the first release to include a patch for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • GraphQL

Affected Vendors

  • GraphQL Foundation