Description
silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS project does not expose a public facing graphql schema, a user account is required to trigger the DDOS attack. If your site is hosted behind a content delivery network (CDN), such as Imperva or CloudFlare, this may further mitigate the risk. This issue has been addressed in versions 3.8.2, 4.1.3, 4.2.5, 4.3.4, and 5.0.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
References (5)
Core 5
Core References
Third Party Advisory x_refsource_confirm
https://github.com/silverstripe/silverstripe-graphql/security/advisories/GHSA-v23w-pppm-jh66
Patch x_refsource_misc
https://github.com/silverstripe/silverstripe-graphql/commit/f6d5976ec4608e51184b0db1ee5b9e9a99d2501c
Mitigation x_refsource_misc
https://docs.silverstripe.org/en/developer_guides/graphql/security_and_best_practices/recursive_or_complex_queries
Third Party Advisory x_refsource_misc
https://github.com/silverstripe/silverstripe-graphql/tree/3.8#recursive-or-complex-queries
Vendor Advisory x_refsource_misc
https://www.silverstripe.org/download/security-releases/CVE-2023-40180
Scores
CVSS v3
7.5
EPSS
0.0068
EPSS Percentile
71.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (2)
silverstripe/graphql
3.0.0 - 3.8.2
silverstripe/graphql
3.0.0 - 3.8.2Packagist
Published
Oct 16, 2023
Tracked Since
Feb 18, 2026