CVE-2024-58365: SurrealDB before 1.2.0 Denial of Service via Nonexistent Function
SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized clients can craft pre-parsed queries invoking nonexistent functions to trigger a panic that crashes the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 1.2.0 - Compensating control
Apply a compensating mitigation by restricting access so that only authorized clients can send queries (since authorized clients can craft pre-parsed queries to trigger the server panic/DoS).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58365?
The severity of CVE-2024-58365 is classified as medium with a score of 6.5.
How does CVE-2024-58365 affect SurrealDB?
CVE-2024-58365 affects SurrealDB by allowing authorized clients to crash the server via calls to nonexistent built-in functions.
What versions of SurrealDB are impacted by CVE-2024-58365?
SurrealDB versions before 1.2.0 are impacted by CVE-2024-58365.
How do I fix CVE-2024-58365?
To fix CVE-2024-58365, upgrade SurrealDB to version 1.2.0 or later.
What type of attack does CVE-2024-58365 enable?
CVE-2024-58365 enables a denial of service attack due to uncaught exceptions in the query executor.