VDB
Sign up
HIGH7.3

GHSA-74cr-77xc-8g6r

Prototype Pollution in @apollo/gateway

Quick fix

GHSA-74cr-77xc-8g6r — @apollo/gateway: upgrade to the fixed version with the command below.

npm install @apollo/gateway@0.6.2

Details

Versions of `@apollo/gateway` prior to 0.6.2 are vulnerable to Prototype Pollution. The package uses deepMerge() to merge objects, which may allow attackers to alter the Object prototype through queries with GraphQL aliases. Carefully constructed payloads can override properties of all objects in the application. This may lead to Denial of Service or may be chained with other vulnerabilities leading to Remote Code Execution.

## Recommendation

Upgrade to version 0.6.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@apollo/gateway
Introduced in: 0Fixed in: 0.6.2
Fixnpm install @apollo/gateway@0.6.2

References