Skip to main content

This site requires you to update your browser. Your browsing experience maybe affected by not having the most up to date version.

CVE-2023-28104 - DDOS attack on graphql endpoints

Severity:
High (?)
Identifier:
CVE-2023-28104
Versions Affected:
4.2.2, 4.1.1
Versions Fixed:
4.2.3, 4.1.2
Release Date:
2023-03-16

An attacker could use a specially crafted graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed and particularly large/complex graphql schemas.

If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this will likely further mitigate the risk.

Base CVSS: 7.5

Reported by: Guy Sartorelli from Silverstripe