CVE-2024-58358: SurrealDB before 2.1.0 Denial of Service via Nonexistent Role
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58358?
CVE-2024-58358 has a severity rating of medium, specifically a score of 6.9.
How do I fix CVE-2024-58358?
To mitigate CVE-2024-58358, upgrade SurrealDB to version 2.1.0 or later.
What type of vulnerability is CVE-2024-58358?
CVE-2024-58358 is a denial of service vulnerability.
Who is primarily affected by CVE-2024-58358?
Privileged owner users in SurrealDB versions before 2.1.0 are primarily affected by CVE-2024-58358.
What happens if CVE-2024-58358 is exploited?
Exploitation of CVE-2024-58358 can lead to an uncaught panic, causing the SurrealDB server to crash.