CVE-2024-58366
9
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| surrealdb | surrealdb | 0 < 1.1.1 | affected |
| surrealdb | surrealdb | 1.1.1 | unaffected |
| surrealdb | surrealdb | 0 < 0.4.2 | affected |
| surrealdb | surrealdb | 0.4.2 | unaffected |
Weaknesses
- CWE-134: Use of Externally-Controlled Format String
References
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-q3gg-m8hr-h4x4
- https://www.vulncheck.com/advisories/surrealdb-before-format-string-via-scripting-functions
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.