PT-2023-27902 · Unknown · Apollo Router

·

CVE-2023-41317

·

Published

2023-09-05

·

Updated

2023-09-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apollo Router versions 1.28.0 through 1.29.0
Description The Apollo Router is subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when GraphQL Subscriptions are enabled. This can be triggered when all of the following conditions are met:
  1. Running an impacted version of Apollo Router;
  2. The Supergraph schema has a subscription type with root-fields defined;
  3. The YAML configuration has subscriptions enabled;
  4. An anonymous subscription operation is received by the Router. There is no data-privacy risk or sensitive-information exposure aspect to this vulnerability.
Recommendations For Apollo Router versions 1.28.0 through 1.29.0, update to version 1.29.1 to resolve the issue. As a temporary workaround, consider disabling subscriptions if they are not necessary for your Graph.

Exploit

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-41317
GHSA-W8VQ-3HF9-XPPX

Affected Products

Apollo Router