Junglewise Threat Intelligence

Apollo Server sensitive information exposure in logging

Severity: info · Published 2023-08-30

Technologies: Apollo Server. Vendors: Apollo.

Executive brief

Apollo Server, a GraphQL server framework, can accidentally log sensitive Studio API keys if those keys contain invalid characters or whitespace. This occurs when schema reporting or usage reporting features are enabled and the API key is malformed. An attacker with access to application logs could retrieve valid API keys, potentially gaining unauthorized access to Apollo Studio account features.

Technical details

The vulnerability is a sensitive information disclosure (CWE-532) in Apollo Server's API key handling. When an Apollo Studio API key contains invalid header characters (per HTTP/header specifications) or leading/trailing whitespace, the node-fetch HTTP client throws an error containing the raw API key value. This error is then logged to the console or configured logging services, exposing the credential. The issue affects users who enable schema reporting or usage reporting features, use the default node-fetch fetcher, and possess an API key with invalid characters. Apollo Server 4.9.3, apollo-server-core 3.12.1, and apollo-server-core 2.26.1 patch the issue by trimming whitespace, validating API keys on startup, and throwing a clear error message if the key is invalid.

Affected products

  • Apollo Server before 4.9.3
  • Apollo apollo-server-core before 2.26.1 or before 3.12.1

Timeline

  • 2023-08-30: disclosed: GHSA-j5g3-5c8r-7qfx published
  • 2023-08-30: patched: Apollo Server 4.9.3, apollo-server-core 2.26.1 and 3.12.1 released

References