Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9567-jfw6-h5pc

Опубликовано: 20 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.

EPSS

Процентиль: 11%
0.00204
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 4.3
nvd
23 дня назад

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.

EPSS

Процентиль: 11%
0.00204
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-613