PT-2024-40134 · Surrealdb · Surrealdb

Published

2024-01-18

·

Updated

2024-01-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: SurrealDB versions prior to 1.1.0
Description: The issue arises when the SurrealQL parser attempts to recursively parse nested statements or idioms without checking the established depth limit, potentially leading to a stack overflow. An authorized attacker may exploit this to crash the server, resulting in denial of service.
Recommendations: For versions prior to 1.1.0, limit the ability of untrusted users to run arbitrary SurrealQL queries to minimize the risk of exploitation. Additionally, ensure the SurrealDB process is configured to automatically restart after a crash to limit the impact of the denial of service.

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

GHSA-6R8P-HPG7-825G

Affected Products

Surrealdb