CVE-2024-58369: SurrealDB before 1.1.1 Denial of Service via Global Parameters
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 1.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58369?
The severity of CVE-2024-58369 is medium with a score of 6.5.
What vulnerability does CVE-2024-58369 represent?
CVE-2024-58369 represents a denial of service vulnerability in SurrealDB versions before 1.1.1 due to improper validation of custom parameters.
How do I fix CVE-2024-58369?
To fix CVE-2024-58369, upgrade SurrealDB to version 1.1.1 or later.
What impact does CVE-2024-58369 have on SurrealDB?
CVE-2024-58369 can cause server panic and denial of service to authorized clients, allowing them to crash the SurrealDB server.
Who is affected by CVE-2024-58369?
Any instance of SurrealDB prior to version 1.1.1 is affected by CVE-2024-58369.