{"id":"GHSA-74hv-qjjq-h7g5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-74hv-qjjq-h7g5","summary":"datasette-graphql leaks details of the schema of private database files","details":"### Impact\n\nWhen running against a Datasette instance with private databases, `datasette-graphql` would expose the schema of those database tables - but not the table contents.\n\n### Patches\n\nPatched in version 1.2.\n\n### Workarounds\n\nThis issue is only present if a Datasette instance that includes private databases and has the `datasette-graphql` plugin installed is available on the public internet. Uninstalling the `datasette-graphql` plugin or preventing public access to the instance can workaround this issue.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [datasette-graphql](https://github.com/simonw/datasette-graphql)\n* Contact [@simonw](https://twitter.com/simonw) by Twitter direct message","published":"2020-11-24T22:59:08Z","modified":"2024-12-02T05:43:35.091839Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"datasette-graphql","fixedVersion":"1.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/simonw/datasette-graphql/security/advisories/GHSA-74hv-qjjq-h7g5"},{"type":"WEB","url":"https://pypi.org/project/datasette-graphql"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:43:35.091839Z"}}