← Back
Database / Storage
CVE-2024-58366 high CVSS 8.5

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...

Summary

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...

AI summary openai / gpt-4o

SurrealDB 1.1.1以前のバージョンには、rquickjsのException::throw_type関数にフォーマット文字列の脆弱性があります。スクリプティング権限を持つ攻撃者は、任意のメモリを読み取ったり、SurrealDBプロセスの権限でコードを実行したりすることが可能です。
❓ What is the problem
フォーマット文字列の脆弱性
📍 Affected scope
SurrealDBのrquickjsのException::throw_type関数
🔥 Severity
攻撃者が任意のメモリを読み取ったり、コードを実行可能
🔧 How to fix
バージョン1.1.1へのアップグレード
🛡️ Workaround
情報なし
🔍 Detection
異常なエラーメッセージやメモリアクセスのログを監視

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →