漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
apollo-compiler Named Fragment Processing Vulnerability
Vulnerability Description
apollo-compiler is a query-based compiler for the GraphQL query language. Prior to 1.27.0, a vulnerability in Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. Named fragments were being processed once per fragment spread in some cases during query validation, leading to exponential resource usage when deeply nested and reused fragments were involved. This could lead to excessive resource consumption and denial of service in applications. This vulnerability is fixed in 1.27.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
apollo-rs 安全漏洞
Vulnerability Description
apollo-rs是Apollo GraphQL开源的一个 Rust 中符合规范的 GraphQL 工具。 apollo-rs 1.27.0之前版本存在安全漏洞,该漏洞源于深层嵌套片段处理不当,可能导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A