CVE-2024-50312

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the attack surface, as it can facilitate the discovery of flaws or errors specific to the application's GraphQL implementation.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*

History

15 Jan 2025, 02:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:0140 -

14 Jan 2025, 13:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:0115 -
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : unknown

30 Oct 2024, 18:35

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2319378 - () https://bugzilla.redhat.com/show_bug.cgi?id=2319378 - Issue Tracking
References () https://github.com/openshift/console/pull/14409/files - () https://github.com/openshift/console/pull/14409/files - Patch
References () https://access.redhat.com/security/cve/CVE-2024-50312 - () https://access.redhat.com/security/cve/CVE-2024-50312 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Redhat openshift Container Platform
Redhat
CWE CWE-200 NVD-CWE-noinfo
CPE cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*

22 Oct 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-22 14:15

Updated : 2025-01-15 02:15


NVD link : CVE-2024-50312

Mitre link : CVE-2024-50312


JSON object : View

Products Affected

redhat

  • openshift_container_platform