Описание
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust server memory and crash the process.
Ссылки
- MitigationVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.0 (исключая)
cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00254
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-674
Связанные уязвимости
CVSS3: 6.5
github
23 дня назад
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply nested type annotations to exhaust server memory and crash the process.
EPSS
Процентиль: 17%
0.00254
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-674