PT-2024-40207 · Surrealdb · Surrealdb

Published

2024-02-21

·

Updated

2024-02-21

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: SurrealDB versions prior to 1.2.1
Description: The issue occurs when handling failed parsing of queries where the error is on a line terminator character, causing the span rendering to panic. This allows a client authorized to run queries in a SurrealDB server to execute a malformed query, leading to a denial of service by crashing the server.
Recommendations: For versions prior to 1.2.1, update to version 1.2.1 or later to resolve the issue. As a temporary workaround, consider limiting the ability of untrusted users to run arbitrary SurrealQL queries. Additionally, ensure that the SurrealDB process is configured to automatically restart after a crash to minimize the impact of the denial of service.

Fix

Weakness Enumeration

Related Identifiers

GHSA-8XFF-473H-F863

Affected Products

Surrealdb