2.14.0
4 years ago
1 months ago
Known vulnerabilities in the @apollo/federation-internals package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@apollo/federation-internals is an Apollo Federation internal utilities Affected versions of this package are vulnerable to Prototype Pollution through incomplete sanitization of input in the query plan execution. An attacker can manipulate the How to fix Prototype Pollution? Upgrade | <2.9.6>=2.10.0-alpha.0 <2.10.5>=2.11.0-preview.0 <2.11.6>=2.12.0-preview.0 <2.12.3>=2.13.0-preview.0 <2.13.2 |