Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q5r-gwcx-24m9

Опубликовано: 20 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.

SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.

EPSS

Процентиль: 21%
0.00287
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
22 дня назад

SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.

EPSS

Процентиль: 21%
0.00287
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200