GraphQL Tools 提供了用于构建、拼接和模拟 GraphQL 模式的工具。在 1.1.35 版本之前, 中的 函数在 Node.js 连接到 端点时,硬编码禁用了 TLS 证书验证。因此,直接使用该执行器或使用 并指定 的应用程序,可能会接受由攻击者控制的证书,当处于网络中间位置的攻击者拦截连接时。这可能导致 或请求头中的认证信息泄露,并且订阅数据可能被篡改。浏览器端的 WebSocket 客户端不受此问题影响,因为浏览器会强制执行证书验证。该问题已在 1.1.35 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| @graphql-tools | executor-legacy-ws | < 1.1.35 |
affected |
| ardatan | graphql-tools | < 1.1.35 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ardatan | graphql-tools | < 1.1.35 | - |
|
| @graphql-tools | executor-legacy-ws | < 1.1.35 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet