CyberRota Analysis
AI-GeneratedThe GraphQL Tools library, prior to version 1.1.35, contains a vulnerability in the executor-legacy-ws buildWSLegacyExecutor() function that disables TLS certificate validation for Node.js connections to WebSocket endpoints. This flaw allows an attacker to intercept connections and potentially disclose sensitive authentication information or modify subscription data. Developers utilizing this library for Node.js applications should prioritize updating to version 1.1.35 to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35.