Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 27 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 26 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hasura:graphql_engine:1.3.3:*:*:*:*:*:*:* |
Tue, 23 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hasura
Hasura graphql Engine |
|
| Vendors & Products |
Hasura
Hasura graphql Engine |
Mon, 22 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server. | |
| Title | Hasura GraphQL 1.3.3 Local File Read via SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:05:38.912Z
Reserved: 2025-12-05T19:10:29.047Z
Link: CVE-2021-47714
Updated: 2025-12-22T21:59:03.356Z
Status : Modified
Published: 2025-12-22T22:15:58.933
Modified: 2025-12-27T17:15:40.340
Link: CVE-2021-47714
No data.
OpenCVE Enrichment
Updated: 2025-12-23T22:40:04Z