The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send queries to the router that uses the @defer or Subscriptions, the Router will panic. To be vulnerable, users of Router must have a coprocessor with coprocessor.supergraph.response configured in their router.yaml and also to support either @defer or Subscriptions. Apollo Router version 1.33.0 has a fix for this vulnerability which was introduced in PR #4014. Users are advised to upgrade. Users unable to upgrade should avoid using the coprocessor supergraph response or disable defer and subscriptions support and continue to use the coprocessor supergraph response.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-754"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45812.json"
}{
"cpe": [
"cpe:2.3:a:apollographql:apollo_router:*:*:*:*:*:*:*:*",
"cpe:2.3:a:apollographql:apollo_helms-charts_router:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.31.0"
},
{
"fixed": "1.33.0"
},
{
"last_affected": "1.32.0"
}
],
"source": [
"AFFECTED_FIELD",
"CPE_RANGE"
]
}