CVE-2023-27588

Source
https://cve.org/CVERecord?id=CVE-2023-27588
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-27588.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-27588
Aliases
  • GHSA-c9rw-rw2f-mj4x
Published
2023-03-14T17:23:10.499Z
Modified
2026-05-15T04:06:36.613317183Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Unauthenticated path traversal vulnerability in Hasura GraphQL Engine
Details

Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4, 2.55.1, 2.20.1, and 2.21.0-beta1. Projects running on Hasura Cloud were not vulnerable. Self-hosted Hasura Projects with deployments that are publicly exposed and not protected by a WAF or other HTTP protection layer should be upgraded to version 1.3.4, 2.55.1, 2.20.1, or 2.21.0-beta1 to receive a patch.

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-27"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27588.json"
}
References

Affected packages