apollo-server@0.3.3 vulnerabilities

Production ready GraphQL Server

  • latest version

    3.13.0

  • first published

    9 years ago

  • latest version published

    2 years ago

  • deprecated

    Package is deprecated

  • licenses detected

    • >=0.2.0-rc.1
  • Direct Vulnerabilities

    Known vulnerabilities in the apollo-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Regular Expression Denial of Service (ReDoS)

    apollo-server is a Production ready GraphQL Server

    Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the startStandaloneServer function. An attacker can cause the server to become unresponsive by sending specially crafted request bodies with exotic character set encodings.

    Note:

    This is only exploitable if the server is configured to use startStandaloneServer directly rather than through integration packages.

    How to fix Regular Expression Denial of Service (ReDoS)?

    A fix was pushed into the master branch but not yet published.

    *
    • H
    Cross-site Scripting (XSS)

    apollo-server is a Production ready GraphQL Server

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Compromised HTTP schema introspection responses or schema prop values with malicious GraphQL type names, may expose a dynamic XSS attack surface that can allow code injection on operation autocomplete.

    How to fix Cross-site Scripting (XSS)?

    Upgrade apollo-server to version 2.25.3, 3.4.1 or higher.

    <2.25.3>=3.0.0 <3.4.1