-
-
Notifications
You must be signed in to change notification settings - Fork 4.8k
Open
Labels
type:bugImpaired feature or lacking behavior that is likely assumedImpaired feature or lacking behavior that is likely assumed
Description
New Issue Checklist
- Report security issues confidentially.
- Any contribution is under this license.
- Before posting search existing issues.
Issue Description
update @apollo/server in v8 version
Logs
@apollo/server 4.2.0 - 4.12.2
Severity: high
Apollo Serve vulnerable to Denial of Service with `startStandaloneServer` - https://github.com/advisories/GHSA-mp6q-xf9x-fwf7
fix available via `npm audit fix --force`
Will install parse-server@9.2.0, which is a breaking change
node_modules/@apollo/server
parse-server 2.2.14 - 9.2.0-alpha.2
Depends on vulnerable versions of @apollo/server
Depends on vulnerable versions of lodash
node_modules/parse-server
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
type:bugImpaired feature or lacking behavior that is likely assumedImpaired feature or lacking behavior that is likely assumed