0.266.0.dev1744797470
6 years ago
5 days ago
Known vulnerabilities in the strawberry-graphql package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
strawberry-graphql is an A library for creating GraphQL APIs Affected versions of this package are vulnerable to Cross-Site Request Forgery (CSRF) due to the default settings of exemption from Django's Note: After the fix, clients need to send CSRF tokens with every request. How to fix Cross-Site Request Forgery (CSRF)? Upgrade | [,0.243.0) |
strawberry-graphql is an A library for creating GraphQL APIs Affected versions of this package are vulnerable to Race Condition when confirming How to fix Race Condition? Upgrade | [,0.193.0) |
strawberry-graphql is an A library for creating GraphQL APIs Affected versions of this package are vulnerable to SQL Injection due to a lack of validations against malicious queries. How to fix SQL Injection? Upgrade | [,0.71.0) |