ZeroHour

CVE-2022-31173

PoC
CVSS 3.1
7.5 high
EPSS
2%p75
Published
()
Modified
Description

Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. This issue has been addressed in version 0.15.10. Users are advised to upgrade. Users unable to upgrade should limit the recursion depth manually.

Vendors
juniper project
Products
juniper
Weakness
CWE-400, CWE-674
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.