{"id":"CVE-2023-34047","aliases":["GHSA-frqc-f2h8-fjvf"],"url":"https://o3.security/vulnerability/CVE-2023-34047","summary":"Exposure of data and identity to wrong session in Spring for GraphQL","details":"A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry.\n","published":"2023-09-20T09:09:12.648Z","modified":"2026-07-15T01:49:19.540046570Z","cvss":{"score":3.1,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework.graphql:spring-graphql","fixedVersion":"1.1.6"},{"ecosystem":"Maven","name":"org.springframework.graphql:spring-graphql","fixedVersion":"1.2.3"}],"fix":null,"references":[{"type":"WEB","url":"https://spring.io/security/cve-2023-34047"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34047.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34047"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:19.540046570Z"}}