Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hasura:graphql_engine:1.3.3:*:*:*:*:*:*:* |
Tue, 23 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hasura
Hasura graphql Engine |
|
| Vendors & Products |
Hasura
Hasura graphql Engine |
Mon, 22 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL definitions to potentially access internal network resources. | |
| Title | Hasura GraphQL 1.3.3 Server-Side Request Forgery via Remote Schema Injection | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-22T22:05:54.146Z
Reserved: 2025-12-05T19:10:29.047Z
Link: CVE-2021-47715
Updated: 2025-12-22T22:00:45.911Z
Status : Analyzed
Published: 2025-12-22T22:15:59.093
Modified: 2025-12-26T16:57:55.427
Link: CVE-2021-47715
No data.
OpenCVE Enrichment
Updated: 2025-12-23T22:40:12Z