Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7991 | API Platform Core does not call GraphQl securityAfterResolver |
Github GHSA |
GHSA-7mxx-3cgm-xxv3 | API Platform Core does not call GraphQl securityAfterResolver |
Mon, 24 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls back to `security`, the impact is there only when there's only a security after resolver and none inside security. The test in version 3.3.8 is probably broken. As of time of publication, a fixed version is not available. | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls back to `security`, the impact is there only when there's only a security after resolver and none inside security. Version 3.3.15 contains a patch for the issue. |
| References |
|
Mon, 24 Mar 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls back to `security`, the impact is there only when there's only a security after resolver and none inside security. The test in version 3.3.8 is probably broken. As of time of publication, a fixed version is not available. | |
| Title | GraphQl securityAfterResolver not called | |
| Weaknesses | CWE-20 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-24T18:03:54.959Z
Reserved: 2025-01-13T17:15:41.050Z
Link: CVE-2025-23204
Updated: 2025-03-24T18:03:51.157Z
Status : Deferred
Published: 2025-03-24T16:15:56.040
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-23204
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:18Z
EUVD
Github GHSA