CVE-2024-58363: SurrealDB before 1.5.4 Authentication Bypass via Database Switch
SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical identifier exists, allowing unauthorized actions if permissions rely solely on the $auth parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58363?
The severity of CVE-2024-58363 is rated as medium with a score of 5.3.
How do I fix CVE-2024-58363?
To remediate CVE-2024-58363, upgrade SurrealDB to version 1.5.4 or later.
What type of attack is associated with CVE-2024-58363?
CVE-2024-58363 is an authentication bypass vulnerability that allows session impersonation.
Which software is affected by CVE-2024-58363?
CVE-2024-58363 affects SurrealDB versions prior to 1.5.4.
How does CVE-2024-58363 impact user security?
CVE-2024-58363 can allow authenticated attackers to impersonate other users across databases.