OSV 1.4.0 · unreviewed · 修改于 2026-09-01 05:31
发布时间
2026-08-28 05:31
GitHub 审查时间
—
NVD 发布时间
2026-08-28 04:17
源文件
advisories/unreviewed/2026/08/GHSA-wfp5-hffg-gvg8/GHSA-wfp5-hffg-gvg8.json
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
该公告没有提供结构化的受影响软件包信息。