Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://groups.google.com/g/hasura-security-announce/c/kzK-uPAKGUU | mailing list third party advisory patch |
https://hasura.io/blog/critical-vulnerability-in-hasuras-graphql-engine-v2-10-0/ | mitigation vendor advisory |
https://github.com/hasura/graphql-engine/security/advisories/GHSA-g7mj-g7f4-hgrg | third party advisory patch |