PT-2024-40134 · Surrealdb · Surrealdb
Published
2024-01-18
·
Updated
2024-01-18
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
SurrealDB versions prior to 1.1.0
Description:
The issue arises when the SurrealQL parser attempts to recursively parse nested statements or idioms without checking the established depth limit, potentially leading to a stack overflow. An authorized attacker may exploit this to crash the server, resulting in denial of service.
Recommendations:
For versions prior to 1.1.0, limit the ability of untrusted users to run arbitrary SurrealQL queries to minimize the risk of exploitation. Additionally, ensure the SurrealDB process is configured to automatically restart after a crash to limit the impact of the denial of service.
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Surrealdb