QID 996201

Date Published: 2023-12-13

QID 996201: Rust (Rust) Security Update for apollo-router (GHSA-w8vq-3hf9-xppx)

This is a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when GraphQL Subscriptions are enabled. It can be triggered when all of the following conditions are met:

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-w8vq-3hf9-xppx for updates and patch information.
    Vendor References

    CVEs related to QID 996201

    Software Advisories
    Advisory ID Software Component Link
    GHSA-w8vq-3hf9-xppx apollo-router URL Logo github.com/advisories/GHSA-w8vq-3hf9-xppx