CVE-2023-22477

CVSS V2 None CVSS V3 None
Description
Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to `/graphql`. This issue was patched in #940. As a workaround, users can disable subscriptions.
Overview
  • CVE ID
  • CVE-2023-22477
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-09T15:15:11
  • Last Modified Date
  • 2023-01-12T21:35:19
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:mercurius_project:mercurius:*:*:*:*:*:node.js:*:* 1 OR 8.13.2
cpe:2.3:a:mercurius_project:mercurius:*:*:*:*:*:node.js:*:* 1 OR 9.0.0 11.5.0
History
Created Old Value New Value Data Type Notes
2023-01-09 15:17:19 Added to TrackCVE
2023-01-09 15:17:19 Weakness Enumeration new
2023-01-09 19:18:21 2023-01-09T19:03:44 CVE Modified Date updated
2023-01-09 19:18:21 Received Awaiting Analysis Vulnerability Status updated
2023-01-12 15:15:47 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-12 22:16:38 2023-01-12T21:35:19 CVE Modified Date updated
2023-01-12 22:16:38 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-12 22:16:39 Weakness Enumeration update
2023-01-12 22:16:42 CPE Information updated