PT-2024-20116 · Unknown · Apollo-Client-Nextjs+1
Ikemurami
·
Published
2024-01-30
·
Updated
2024-02-06
·
CVE-2024-23841
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
apollo-client-nextjs versions prior to 0.7.0
Description
The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. This issue arises from improper handling of untrusted input when the package performs server-side rendering of HTML pages. To exploit this vulnerability, an attacker would need to either inject malicious input or arrange to have malicious input be returned by a GraphQL server.
Recommendations
To fix this issue, please update to version 0.7.0 or later.
As a temporary workaround is not available, updating to the fixed version is the only recommended course of action.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Apollo/Experimental-Apollo-Client-Nextjs
Apollo-Client-Nextjs