CVE-2022-46792

HIGH

Hasura GraphQL Engine <2.15.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)

Scores

CVSS v3 8.8
EPSS 0.0081
EPSS Percentile 52.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (3)
hasura/graphql_engine 2.12.0 (2 CPE variants)
hasura/graphql_engine 2.14.0 (3 CPE variants)
hasura/graphql_engine 2.10.0 - 2.10.2
Published Dec 08, 2022
Tracked Since Feb 18, 2026