cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses @flexSearchFulltext, users of that schema may be able to inject arbitrary AQL queries that will be forwarded to and executed by ArangoDB. Schemas that do not use @flexSearchFulltext are not affected. The attacker needs to have READ permission to at least one root entity type that has @flexSearchFulltext enabled. The issue has been fixed in version 3.0.2 and in version 2.7.0 of cruddl. As a workaround, users can temporarily remove @flexSearchFulltext from their schemas.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-74",
"CWE-943"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36084.json"
}{
"cpe": "cpe:2.3:a:aeb:cruddl:*:*:*:*:*:node.js:*:*",
"extracted_events": [
{
"introduced": "1.1.0"
},
{
"fixed": "2.7.0"
},
{
"introduced": "3.0.0"
},
{
"fixed": "3.0.2"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}