Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-43783

Опубликовано: 27 авг. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if all of the following are true: 1. The Apollo Router has been configured to support External Coprocessing. 2. The Apollo Router has been configured to send request bodies to coprocessors. This is a non-default configuration and must be configured intentionally by administrators. Instances of the Apollo Router running versions >=1.7.0 and <1.52.1 are impacted by a denial-of-service vulnerability if all of the following are true: 1. Router has been configured to use a custom-developed Native Rust Plugin. 2. The plugin accesses Request.router_request in the RouterService layer. 3. You are accumulating the body from Request.router_request into memory.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apollographql:apollo-router:*:*:*:*:*:rust:*:*
Версия от 1.7.0 (включая) до 1.52.1 (исключая)
cpe:2.3:a:apollographql:apollo_helms-charts_router:*:*:*:*:*:*:*:*
Версия от 1.7.0 (включая) до 1.52.1 (исключая)
cpe:2.3:a:apollographql:apollo_router:*:*:*:*:*:*:*:*
Версия от 1.7.0 (включая) до 1.52.1 (исключая)

EPSS

Процентиль: 70%
0.00625
Низкий

7.5 High

CVSS3

Дефекты

CWE-770
CWE-770

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

Apollo Router Coprocessors may cause Denial-of-Service when handling request bodies

EPSS

Процентиль: 70%
0.00625
Низкий

7.5 High

CVSS3

Дефекты

CWE-770
CWE-770