CVE-2024-58356

Summary

SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE … OVERWRITE clause is used on tables defined with TYPE RELATION. Because table definitions include the PERMISSIONS clause, an attempt to tighten a table's permissions via OVERWRITE does not take effect, and the administrator may incorrectly believe the change was applied. As a result, a client authorized to run queries may continue to access data in that table that the updated (but unapplied) permissions were intended to restrict.

Affected Software

VendorProductVersion RangeStatus
surrealdbsurrealdb0 < 2.1.4affected
surrealdbsurrealdb2.1.4unaffected
surrealdbsurrealdb0 < 2.1.4affected
surrealdbsurrealdb2.1.4unaffected

Weaknesses

  • CWE-276: Incorrect Default Permissions

References