Improper Input Validation Affecting cruddl package, versions >=1.1.0 <2.7.0 >=3.0.0 <3.0.1
Threat Intelligence
EPSS
0.22% (62nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-CRUDDL-3019825
- published 9 Sep 2022
- disclosed 9 Sep 2022
- credit Unknown
How to fix?
Upgrade cruddl
to version 2.7.0, 3.0.1 or higher.
Overview
cruddl is a [![Package Quality](https://npm.
Affected versions of this package are vulnerable to Improper Input Validation. If it is used to generate a schema that uses @flexSearchFulltext
, users of that schema may be able to inject arbitrary AQL queries that will be forwarded to and executed by ArangoDB.
Note: Schemas that do not use @flexSearchFulltext
are not affected, and an attacker needs to have READ
permission to at least one root entity type that has @flexSearchFulltext
enabled.
References
CVSS Scores
version 3.1