Описание
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.
Ссылки
- Vendor AdvisoryMitigation
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.0 (исключая)
cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00359
Низкий
7.5 High
CVSS3
Дефекты
CWE-674
Связанные уязвимости
CVSS3: 7.5
github
23 дня назад
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated attackers can send deeply nested JSON payloads to the WebSocket /rpc endpoint to exhaust server memory and crash the process.
EPSS
Процентиль: 29%
0.00359
Низкий
7.5 High
CVSS3
Дефекты
CWE-674