CVE-2022-30288

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/05/2022
Last modified:
22/08/2024

Description

Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the vendor has disputed this on the grounds that it is not the server's responsibility to "enforce all the various ways a developer could write code with logic errors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ohler:agoo:*:*:*:*:*:ruby:*:* 2.14.3 (excluding)