CVE-2024-58366: SurrealDB before 1.1.1 Format String via Scripting Functions
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throwtype function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 1.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58366?
The severity of CVE-2024-58366 is rated high with a score of 8.5.
How do I fix CVE-2024-58366?
To mitigate CVE-2024-58366, upgrade to SurrealDB version 1.1.1 or later.
What are the risks associated with CVE-2024-58366?
CVE-2024-58366 allows attackers with scripting privileges to exploit a format string vulnerability, potentially leading to arbitrary memory read or code execution.
Which versions of SurrealDB are affected by CVE-2024-58366?
CVE-2024-58366 affects SurrealDB versions prior to 1.1.1.
What function is vulnerable in CVE-2024-58366?
The vulnerability in CVE-2024-58366 resides in the rquickjs Exception::throw_type function when scripting is enabled.