Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-656c-777j-wp92

Опубликовано: 06 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Agoo through 2.14.2 does not reject GraphQL fragment spreads that form cycles, leading to an application crash.

Agoo through 2.14.2 does not reject GraphQL fragment spreads that form cycles, leading to an application crash.

EPSS

Процентиль: 58%
0.00367
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the vendor has disputed this on the grounds that it is not the server's responsibility to "enforce all the various ways a developer could write code with logic errors.

EPSS

Процентиль: 58%
0.00367
Низкий

7.5 High

CVSS3