Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-98f8-j56x-2hh4

Опубликовано: 26 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.7

Описание

Duplicate Advisory: SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7vm2-j586-vcvc. This link is maintained to preserve external references.

Original Description

A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records.

Пакеты

Наименование

surrealdb

rust
Затронутые версииВерсия исправления

>= 2.3.0

Отсутствует

5.7 Medium

CVSS3

Дефекты

CWE-863

5.7 Medium

CVSS3

Дефекты

CWE-863