Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the vendor has disputed this on the grounds that it is not the server's responsibility to "enforce all the various ways a developer could write code with logic errors.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-22T14:47:12.339Z
Reserved: 2022-05-04T00:00:00
Link: CVE-2022-30288
Updated: 2024-08-03T06:48:36.303Z
Status : Modified
Published: 2022-05-04T23:15:08.500
Modified: 2024-11-21T07:02:30.380
Link: CVE-2022-30288
No data.
OpenCVE Enrichment
No data.
Weaknesses