apollo-server@0.3.3 vulnerabilities

Production ready GraphQL Server

Direct Vulnerabilities

Known vulnerabilities in the apollo-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Cross-site Scripting (XSS)

apollo-server is a Production ready GraphQL Server

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Compromised HTTP schema introspection responses or schema prop values with malicious GraphQL type names, may expose a dynamic XSS attack surface that can allow code injection on operation autocomplete.

How to fix Cross-site Scripting (XSS)?

Upgrade apollo-server to version 2.25.3, 3.4.1 or higher.

<2.25.3 >=3.0.0 <3.4.1