VYPR
High severity7.5NVD Advisory· Published Jul 29, 2019· Updated Jun 17, 2026

CVE-2019-1020015

CVE-2019-1020015

Description

graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:hasura:graphql_engine:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:hasura:graphql_engine:*:*:*:*:*:*:*:*range: <1.0.0
    • cpe:2.3:a:hasura:graphql_engine:1.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:hasura:graphql_engine:1.0.0:beta.1:*:*:*:*:*:*
    • cpe:2.3:a:hasura:graphql_engine:1.0.0:beta.2:*:*:*:*:*:*
    • (no CPE)range: <1.0.0-beta.3
  • graphql-engine/graphql-enginev5
    Range: < 1.0.0-beta.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.