Executive Summary

Informations
Name CVE-2025-23204 First vendor Publication 2025-03-24
Vendor Cve Last vendor Modification 2025-03-24

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls back to `security`, the impact is there only when there's only a security after resolver and none inside security. Version 3.3.15 contains a patch for the issue.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-23204

Sources (Detail)

https://github.com/api-platform/core/commit/dc4fc84ba93e22b4f44a37e90a93c6d07...
https://github.com/api-platform/core/pull/6444
https://github.com/api-platform/core/pull/6444/files#diff-09e3c2cfe12a2ce65bd...
https://github.com/api-platform/core/security/advisories/GHSA-7mxx-3cgm-xxv3
https://github.com/soyuka/core/blob/7e2e8f9ff322ac5f6eb5f65baf432bffdca0fd51/...
Source Url

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2025-03-25 00:20:30
  • First insertion