← Back
Database / Storage
CVE-2024-58362 high CVSS 8.8

SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...

Summary

SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...

AI summary openai / gpt-4o

SurrealDBのバージョン1.5.5未満および2.0.0-beta.3未満では、RPC APIのサインインおよびサインアップ操作において、任意のオブジェクトが再帰的な検証を受けずに受け入れられる。このため、未認証の攻撃者がbincodeシリアル化フォーマットを使用してバイナリオブジェクトを作成し、サインイン/サインアップクエリの中に含まれるサブクエリとして送信できる。この結果、攻撃者はデータベースの所有者としてシステムユーザーセッションで操作を実行可能となる。
❓ What is the problem
SurrealDBのRPC APIにおけるサインイン/サインアップ操作の入力が再帰的に検証されない脆弱性。
📍 Affected scope
SurrealDBバージョン1.5.5未満および2.0.0-beta.3未満。
🔥 Severity
高。攻撃者がbincodeシリアル化フォーマットを通じて非認証で操作可能。
🔧 How to fix
バージョン1.5.5もしくは2.0.0-beta.3以上にアップデートする。
🛡️ Workaround
情報なし
🔍 Detection
サーバーログを確認し、不審なクエリを特定する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →