CVE-2024-58367: SurrealDB before 2.0.4 Improper Authorization via SELECT Permissions
SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques. Attackers can exploit SELECT VALUE operations, field aliasing, function arguments, WHERE clause filtering, RETURN BEFORE clauses, and SET clause references to leak protected field contents despite lacking SELECT permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 2.0.4 - Compensating control
For SurrealDB instances that are still on versions before 2.0.4, restrict access so that users who have access to SELECT permissions cannot reach queries that leverage field aliasing, function arguments, WHERE clause filtering, RETURN BEFORE clauses, or SET clause references to extract protected field contents.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58367?
The severity of CVE-2024-58367 is classified as high with a score of 7.1.
How do I fix CVE-2024-58367?
To fix CVE-2024-58367, upgrade to SurrealDB version 2.0.4 or later.
What type of attack can be performed using CVE-2024-58367?
Using CVE-2024-58367, attackers can exploit improper authorization to access unauthorized field values during SELECT, UPDATE, and DELETE operations.
Which versions of SurrealDB are affected by CVE-2024-58367?
CVE-2024-58367 affects all versions of SurrealDB prior to 2.0.4.
What kind of vulnerabilities does CVE-2024-58367 present for users?
CVE-2024-58367 presents vulnerabilities that allow authorized users to access unauthorized data, compromising data integrity and confidentiality.