We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-23204

GraphQl securityAfterResolver not called



Description

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls back to `security`, the impact is there only when there's only a security after resolver and none inside security. Version 3.3.15 contains a patch for the issue.

Reserved 2025-01-13 | Published 2025-03-24 | Updated 2025-03-24 | Assigner GitHub_M


MEDIUM: 4.4CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-20: Improper Input Validation

Product status

>= 3.3.8, < 3.3.15
affected

References

github.com/...m/core/security/advisories/GHSA-7mxx-3cgm-xxv3

github.com/api-platform/core/pull/6444

github.com/api-platform/core/pull/6444/files

github.com/...ommit/dc4fc84ba93e22b4f44a37e90a93c6d079c1c620

github.com/...mfony/Security/State/AccessCheckerProvider.php

cve.org (CVE-2025-23204)

nvd.nist.gov (CVE-2025-23204)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-23204

Support options

Helpdesk Chat, Email, Knowledgebase