Threat Advisory

GraphQL Tools TLS Certificate Validation Disabled in Legacy WebSocket Executor

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, assigned a CVSS score of 7.4, exists in the @graphql-tools/executor-legacy-ws package that allows a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications using this executor with a wss:// endpoint, enabling interception of credentials and tampering with subscription data; affected versions include <= 1.1.34, where TLS certificate validation is disabled by default, allowing an attacker to exploit the flaw via WebSocket connections over WSS; business impact includes potential compromise of sensitive information passed over the connection.

RECOMMENDATION:

We recommend you to update @graphql-tools/executor-legacy-ws to version 1.1.35.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, assigned a CVSS score of 7.4, exists in the @graphql-tools/executor-legacy-ws package that allows a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications using this executor with a wss:// endpoint, enabling interception of credentials and tampering with subscription data; affected versions include <= 1.1.34, where TLS certificate validation is disabled by default, allowing an attacker to exploit the flaw via WebSocket connections over WSS; business impact includes potential compromise of sensitive information passed over the connection.

RECOMMENDATION:

We recommend you to update @graphql-tools/executor-legacy-ws to version 1.1.35.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu