Описание
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.
EPSS
Процентиль: 16%
0.00249
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-248
Связанные уязвимости
CVSS3: 6.5
github
13 дней назад
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.
EPSS
Процентиль: 16%
0.00249
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-248