Описание
SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elements instead of hiding them. Attackers with record scope access can read array elements that element-level permissions should deny by exploiting incorrect index handling during permission filtering.
Ссылки
- Vendor AdvisoryMitigation
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.4 (исключая)
cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00258
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 6.5
github
22 дня назад
SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elements instead of hiding them. Attackers with record scope access can read array elements that element-level permissions should deny by exploiting incorrect index handling during permission filtering.
EPSS
Процентиль: 17%
0.00258
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-863