datasette-graphql leaks details of the schema of private database files
Low severity
GitHub Reviewed
Published
Nov 21, 2020
in
simonw/datasette-graphql
•
Updated Jan 9, 2023
Description
Reviewed
Nov 24, 2020
Published to the GitHub Advisory Database
Nov 24, 2020
Last updated
Jan 9, 2023
Impact
When running against a Datasette instance with private databases,
datasette-graphql
would expose the schema of those database tables - but not the table contents.Patches
Patched in version 1.2.
Workarounds
This issue is only present if a Datasette instance that includes private databases and has the
datasette-graphql
plugin installed is available on the public internet. Uninstalling thedatasette-graphql
plugin or preventing public access to the instance can workaround this issue.For more information
If you have any questions or comments about this advisory:
References