{"id":"CVE-2022-36084","summary":"cruddl vulnerable to AQL injection through flexSearch","details":"cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`, users of that schema may be able to inject arbitrary AQL queries that will be forwarded to and executed by ArangoDB. Schemas that do not use `@flexSearchFulltext` are not affected. The attacker needs to have `READ` permission to at least one root entity type that has `@flexSearchFulltext` enabled. The issue has been fixed in version 3.0.2 and in version 2.7.0 of cruddl. As a workaround, users can temporarily remove `@flexSearchFulltext` from their schemas.","aliases":["GHSA-qm4w-4995-vg7f"],"modified":"2026-08-12T03:51:40.289955497Z","published":"2022-09-08T21:15:13Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36084.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-74","CWE-943"]},"references":[{"type":"ADVISORY","url":"https://github.com/AEB-labs/cruddl/security/advisories/GHSA-qm4w-4995-vg7f"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36084.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36084"},{"type":"FIX","url":"https://github.com/AEB-labs/cruddl/commit/13b9233733ed6fc822718a07bc90a80cd3492698"},{"type":"FIX","url":"https://github.com/AEB-labs/cruddl/pull/253"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aeb-labs/cruddl","events":[{"introduced":"3b40019039d9f00b09b2139da4c0364147d5a684"},{"fixed":"c4ecd89f010fc1b685792bcd544130ce8f5bc185"},{"introduced":"3471d6a6d6bd8933238b1fa888477684cc7ba176"},{"fixed":"1914e8897e99e429340f16716b2b2ca9de63162c"},{"fixed":"13b9233733ed6fc822718a07bc90a80cd3492698"}],"database_specific":{"extracted_events":[{"introduced":"1.1.0"},{"fixed":"2.7.0"},{"introduced":"3.0.0"},{"fixed":"3.0.2"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:aeb:cruddl:*:*:*:*:*:node.js:*:*"}}],"versions":["v3.0.1","v2.7.0-alpha.1","v3.0.0","v2.7.0-alpha.0","v2.6.0","v2.6.0-alpha.4","v2.6.0-alpha.3","v2.6.0-alpha.2","v2.6.0-alpha.1","v2.6.0-alpha.0","v2.5.0","v2.5.0-alpha.2","v2.5.0-alpha.1","v2.5.0-alpha.0","v2.4.1","v2.4.0","v2.4.0-alpha.2","v2.4.0-alpha.1","v2.4.0-alpha.0","v2.3.0","v2.3.0-alpha.3","v2.3.0-alpha.2","v2.3.0-alpha.1","v2.3.0-alpha.0","v2.2.0","v2.2.0-alpha.3","v2.2.0-alpha.2","v2.2.0-alpha.1","v2.2.0-alpha.0","v2.1.0","v2.1.0-alpha.2","v2.1.0-alpha.1","v2.1.0-alpha.0","v2.0.0","v2.0.0-alpha.5","v2.0.0-alpha.4","v2.0.0-alpha.3","v2.0.0-alpha.2","v2.0.0-alpha.1","v2.0.0-alpha.0","v1.7.6","v1.7.5","v1.7.4","v1.7.3","v1.7.2","v1.7.0","v1.6.0","v1.5.1","v1.5.0","v1.4.1","v1.4.0","v1.3.3","v1.3.2","v1.3.1","v1.3.0","v1.2.8","v1.2.7","v1.2.6","v1.2.5","v1.2.4","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.2.0-alpha.3","v1.2.0-alpha.2","v1.2.0-alpha.1","v1.2.0-alpha.0","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36084.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}