Skip to content

Commit f958c82

Browse files
committed
add CVE-2025-31481 and CVE-2025-31485 for API Platform
1 parent 2f761bf commit f958c82

File tree

4 files changed

+56
-0
lines changed

4 files changed

+56
-0
lines changed

api-platform/core/CVE-2025-31481.yaml

+14
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
title: "GraphQL query operations security can be bypassed"
2+
link: https://github.com/advisories/GHSA-cg3c-245w-728m
3+
cve: CVE-2025-31481
4+
branches:
5+
'3.4':
6+
time: 2025-04-03 15:02:00
7+
versions: ['>=3.4.0', '<3.4.17']
8+
'4.0':
9+
time: 2025-04-03 15:02:00
10+
versions: ['>=4.0.0', '<4.0.22']
11+
'4.1':
12+
time: 2025-04-03 15:03:00
13+
versions: ['>=4.1.0', '<4.1.5']
14+
reference: composer://api-platform/core

api-platform/core/CVE-2025-31485.yaml

+14
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
title: "GraphQL grant on a property might be cached with different objects"
2+
link: https://github.com/api-platform/core/security/advisories/GHSA-428q-q3vv-3fq3
3+
cve: CVE-2025-31485
4+
branches:
5+
'3.4':
6+
time: 2025-04-03 15:03:00
7+
versions: ['>=3.4.0', '<3.4.17']
8+
'4.0':
9+
time: 2025-04-03 15:03:00
10+
versions: ['>=4.0.0', '<4.0.22']
11+
'4.1':
12+
time: 2025-04-03 15:03:00
13+
versions: ['>=4.1.0', '<4.1.5']
14+
reference: composer://api-platform/core
+14
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
title: "GraphQL query operations security can be bypassed"
2+
link: https://github.com/advisories/GHSA-cg3c-245w-728m
3+
cve: CVE-2025-31481
4+
branches:
5+
'3.4':
6+
time: 2025-04-03 15:02:00
7+
versions: ['>=3.4.0', '<3.4.17']
8+
'4.0':
9+
time: 2025-04-03 15:02:00
10+
versions: ['>=4.0.0', '<4.0.22']
11+
'4.1':
12+
time: 2025-04-03 15:03:00
13+
versions: ['>=4.1.0', '<4.1.5']
14+
reference: composer://api-platform/graphql
+14
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
title: "GraphQL grant on a property might be cached with different objects"
2+
link: https://github.com/api-platform/core/security/advisories/GHSA-428q-q3vv-3fq3
3+
cve: CVE-2025-31485
4+
branches:
5+
'3.4':
6+
time: 2025-04-03 15:03:00
7+
versions: ['>=3.4.0', '<3.4.17']
8+
'4.0':
9+
time: 2025-04-03 15:03:00
10+
versions: ['>=4.0.0', '<4.0.22']
11+
'4.1':
12+
time: 2025-04-03 15:03:00
13+
versions: ['>=4.1.0', '<4.1.5']
14+
reference: composer://api-platform/graphql

0 commit comments

Comments
 (0)