GHSA-w42g-7vfc-xf37
MediumAdvisory
Published 5 Jun 2020In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- —
- probability of exploitation
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 3
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Introspection in schema validation in Apollo Server
Carried by container images the latest versions of 3 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| apollo-server-expressnpm | 1.4.0, 2.9.16 | 2.14.2 | 5 |
| apollo-server-corenpm | 1.3.6, 1.4.0 | 2.14.2 | 2 |
| apollo-server-lambdanpm | 1.3.6 | 2.14.2 | 1 |
- OSV records
- GHSA-w42g-7vfc-xf37
Charts affected
3 by stars
Container images carrying it
6 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| assistiot/ | 0570b27bb7c2 | apollo-server-core | 2.14.2 | 1 |
| hansehe/ | 58e09540afbc | apollo-server-core apollo-server-express apollo-server-lambda | 2.14.2 2.14.2 2.14.2 | 1 |
| ghcr.io/ | 0635f17c9d2c | apollo-server-express | 2.14.2 | 1 |
| ghcr.io/ | e34964e336c1 | apollo-server-express | 2.14.2 | 1 |
| ghcr.io/ | 0c5a3398d1e4 | apollo-server-express | 2.14.2 | 1 |
| ghcr.io/ | 8ba040e79ca0 | apollo-server-express | 2.14.2 | 1 |