CVE-2024-58359: SurrealDB before 2.1.0 Denial of Service via rand() Sorting
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries with ORDER BY rand() to trigger a panic in the sorting function, crashing the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 2.1.0 - Compensating control
Avoid using the ORDER BY rand() clause with SurrealDB until upgraded, since it can trigger a panic in the sorting function and crash the server.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58359?
CVE-2024-58359 has a high severity rating of 7.1.
What type of vulnerability is CVE-2024-58359?
CVE-2024-58359 is a denial of service vulnerability in SurrealDB.
How do I fix CVE-2024-58359?
To fix CVE-2024-58359, upgrade to SurrealDB version 2.1.0 or later.
What triggers the denial of service in CVE-2024-58359?
The denial of service is triggered when executing queries with the ORDER BY rand() clause in SurrealDB.
What versions of SurrealDB are affected by CVE-2024-58359?
SurrealDB versions before 2.1.0 are affected by CVE-2024-58359.