A high-severity vulnerability, assigned a CVSS score of 7.4, exists in the @graphql-tools/executor-legacy-ws package that allows a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications using this executor with a wss:// endpoint, enabling interception of credentials and tampering with subscription data; affected versions include <= 1.1.34, where TLS certificate validation is disabled by default, allowing an attacker to exploit the flaw via WebSocket connections over WSS; business impact includes potential compromise of sensitive information passed over the connection.
We recommend you to update @graphql-tools/executor-legacy-ws to version 1.1.35.[/subscribe_to_unlock_form]
A high-severity vulnerability, assigned a CVSS score of 7.4, exists in the @graphql-tools/executor-legacy-ws package that allows a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications using this executor with a wss:// endpoint, enabling interception of credentials and tampering with subscription data; affected versions include <= 1.1.34, where TLS certificate validation is disabled by default, allowing an attacker to exploit the flaw via WebSocket connections over WSS; business impact includes potential compromise of sensitive information passed over the connection.
We recommend you to update @graphql-tools/executor-legacy-ws to version 1.1.35.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]