An attacker could use a specially crafted graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed and particularly large/complex graphql schemas.
If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this will likely further mitigate the risk.
Upgrade to silverstripe/graphql 4.2.3 or 4.1.2 or above to remedy the vulnerability.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-770"
],
"severity": "HIGH",
"nvd_published_at": "2023-03-16T16:15:00Z",
"github_reviewed_at": "2023-03-16T17:22:17Z"
}