Описание
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.1 (исключая)
cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.0045
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-248
Связанные уязвимости
CVSS3: 6.5
github
2 месяца назад
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.
EPSS
Процентиль: 37%
0.0045
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-248