GHSA-74cr-77xc-8g6r

Suggest an improvement
Source
https://github.com/advisories/GHSA-74cr-77xc-8g6r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-74cr-77xc-8g6r/GHSA-74cr-77xc-8g6r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-74cr-77xc-8g6r
Published
2019-06-13T20:37:39Z
Modified
2021-08-16T15:28:22Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Prototype Pollution in @apollo/gateway
Details

Versions of @apollo/gateway prior to 0.6.2 are vulnerable to Prototype Pollution. The package uses deepMerge() to merge objects, which may allow attackers to alter the Object prototype through queries with GraphQL aliases. Carefully constructed payloads can override properties of all objects in the application. This may lead to Denial of Service or may be chained with other vulnerabilities leading to Remote Code Execution.

Recommendation

Upgrade to version 0.6.2 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-1321",
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-13T20:37:08Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / @apollo/gateway

Package

Name
@apollo/gateway
View open source insights on deps.dev
Purl
pkg:npm/%40apollo/gateway

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.6.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-74cr-77xc-8g6r/GHSA-74cr-77xc-8g6r.json"