Description
Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2817 | Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. |
Github GHSA |
GHSA-v9jh-j8px-98vq | go-ethereum vulnerable to denial of service via crafted GraphQL query |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-13T16:28:14.721Z
Reserved: 2023-09-08T00:00:00.000Z
Link: CVE-2023-42319
Updated: 2024-08-02T19:16:51.000Z
Status : Modified
Published: 2023-10-18T06:15:07.893
Modified: 2024-11-21T08:22:25.583
Link: CVE-2023-42319
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA