Junglewise Threat Intelligence

CVE-2024-23841: Apollo experimental-nextjs-app-support cross-site scripting in server-side rendering

CVE-2024-23841 · Severity: low · CVSS 3.1 · Published 2024-01-30

Vendors: Apollo, npm.

Executive brief

The @apollo/experimental-nextjs-app-support library, used to integrate Apollo GraphQL with Next.js applications, contains a cross-site scripting (XSS) vulnerability in its server-side rendering functionality. An attacker can inject malicious JavaScript code into rendered HTML pages by exploiting improper input handling, potentially allowing them to steal session data, perform actions on behalf of users, or redirect users to malicious sites. This vulnerability affects all versions up to 0.6.0 and is fixed in version 0.7.0.

Technical details

The vulnerability is a reflected/stored cross-site scripting (CWE-79) flaw in @apollo/experimental-nextjs-app-support's server-side rendering implementation. The library fails to properly escape or sanitize untrusted input before inserting it into HTML output sent to browsers. An attacker can craft malicious input (e.g., via GraphQL queries or URL parameters) that contains JavaScript code, which will be executed in the victim's browser when the server-rendered page is loaded. No privileges or user interaction are required; the vulnerability is network-reachable and affects confidentiality (session hijacking, credential theft) and integrity (DOM manipulation, form tampering). The fix, released in version 0.7.0, implements proper HTML escaping to neutralize JavaScript injection attempts.

Affected products

  • Apollo experimental-nextjs-app-support <= 0.6.0

Timeline

  • 2024-01-30: disclosed
  • 2024-01-30: patched: Version 0.7.0 released

References