AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-CWE-200

GraphQL Field Suggestions Enabled

Severity:
Medium
Summary

Your web application is running with GraphQL Field Suggestions enabled in a production environment.

GraphQL Field Suggestions is a feature that provides clients with suggested field names when an invalid or non-existent field is queried. This feature can help developers identify available fields and navigate the API more effectively.

However, in a production environment, exposing field suggestions may pose a security risk, as attackers could use the suggested field names to gather information about the API's structure and potentially craft targeted attacks, exploit other vulnerabilities, or gain unauthorized access to protected resources. It is essential to disable or restrict access to field suggestions in production environments to prevent unauthorized access and information leakage.

Impact

Enabling GraphQL Field Suggestions in a production environment can lead to unauthorized access to sensitive schema information, potentially revealing the underlying structure and data types of the API. Attackers can use this information to craft targeted attacks, exploit other vulnerabilities within the system, or gain unauthorized access to protected resources.

Remediation

Disable Field Suggestions: Ensure that GraphQL Field Suggestions are disabled or restricted in production environments. Keep this feature enabled only in development or staging environments where access is limited to authorized personnel.

Required Skills for Successful Exploitation
Actions To Take
Vulnerability Index

You can search and find all vulnerabilities

Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

No items found.