CVE-2024-50311: Graphql: denial of service (dos) vulnerability via graphql batching
A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue causes excessive resource consumption, leading to application unavailability for legitimate users.
Other sources
Denial of Service (DoS) vulnerability via GraphQL Batching was identified. The application allows multiple queries to be sent within a single request, which enables an attacker to submit a request containing thousands of aliases in one query. Exploitation of this vulnerability results in a complete denial of access to the application for legitimate users.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50311?
The severity of CVE-2024-50311 is classified as a denial of service (DoS) vulnerability.
How do I fix CVE-2024-50311?
To address CVE-2024-50311, update your Red Hat OpenShift Container Platform to the latest version that resolves this vulnerability.
What is the impact of CVE-2024-50311?
CVE-2024-50311 allows attackers to send multiple queries in a single request, leading to potential service disruption.
Which versions of OpenShift are affected by CVE-2024-50311?
CVE-2024-50311 affects Red Hat OpenShift Container Platform version 4.0.
Is there a workaround for CVE-2024-50311?
Currently, there are no specific workarounds available for mitigating CVE-2024-50311 other than applying the recommended updates.