QID 996221
Date Published: 2023-12-13
QID 996221: Rust (Rust) Security Update for apollo-router (GHSA-r344-xw3p-2frj)
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send queries to the router that uses the @defer or Subscriptions, the Router will panic.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-r344-xw3p-2frj for updates and patch information.
Vendor References
- GHSA-r344-xw3p-2frj -
github.com/advisories/GHSA-r344-xw3p-2frj
CVEs related to QID 996221
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r344-xw3p-2frj | apollo-router |
|