CVE-2021-47714

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hasura:graphql_engine:1.3.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-22 22:15

Updated : 2025-12-27 17:15


NVD link : CVE-2021-47714

Mitre link : CVE-2021-47714

CVE.ORG link : CVE-2021-47714


JSON object : View

Products Affected

hasura

  • graphql_engine
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')