Vulnerabilities (CVE)

Filtered by vendor Hasura Subscribe
Filtered by product Graphql Engine
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-46792 1 Hasura 1 Graphql Engine 2023-08-08 N/A 8.8 HIGH
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)
CVE-2019-1020015 1 Hasura 1 Graphql Engine 2021-07-21 5.0 MEDIUM 7.5 HIGH
graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.