The Paradox of Disabling GraphQL Introspection: Lessons from the Parse Server GraphQL API vulnerability

The Paradox of Disabling GraphQL Introspection: Lessons from the Parse Server GraphQL API vulnerability

Last week, the security community was alerted to a vulnerability in Parse Server GraphQL API, which allowed public access to the GraphQL schema without requiring a session token or the master key ...