CVE-2024-58358
EUVD-2024-5567518.07.2026, 14:17
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| surrealdb | surrealdb | 𝑥 < 2.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration