CVE-2024-47082
CVSS 3.1 Score 8 of 10 (high)
Details
Summary
CVE-2024-47082 is a vulnerability affecting the Strawberry GraphQL library before version 0.243.0. By default, these integrations enabled multipart file uploads, making them susceptible to Cross-Site Request Forgery (CSRF) attacks. The Django HTTP view integration had an additional exemption for Django's built-in CSRF protection, further increasing the risk. As a result, all Strawberry integrations were vulnerable to CSRF attacks without the explicit enabling of security mechanisms. Version 0.243.0 is the first release to include a patch for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GraphQL
Affected Vendors
- GraphQL Foundation