Junglewise Threat Intelligence

CVE-2022-36084: cruddl AQL injection through flexSearch

CVE-2022-36084 · Severity: low · CVSS 3.1 · Published 2022-09-16

Executive brief

cruddl is a GraphQL API generator for ArangoDB databases. A vulnerability in the flexSearch feature allows authenticated users with read permissions to inject arbitrary database queries that bypass normal safeguards, potentially exposing or modifying sensitive data stored in the underlying database.

Technical details

The vulnerability is an AQL (ArangoDB Query Language) injection flaw in cruddl's @flexSearchFulltext decorator. When a schema uses this decorator, the library fails to properly sanitize user-supplied search input before constructing database queries. An attacker with READ permission to a root entity type with @flexSearchFulltext enabled can craft malicious input to inject arbitrary AQL commands that are forwarded directly to ArangoDB for execution. This allows full compromise of database confidentiality, integrity, and availability. The issue has been patched in versions 2.7.0 and 3.0.2.

Affected products

  • AEB-labs cruddl >=1.1.0, <2.7.0 and >=3.0.0, <3.0.2

Timeline

  • 2022-09-08: disclosed: NVD publication date
  • 2022-09-16: disclosed: GHSA publication date
  • 2022-09-16: patched: Patches released in versions 2.7.0 and 3.0.2

References