CVE-2024-58363

EUVD-2024-55679
SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical identifier exists, allowing unauthorized actions if permissions rely solely on the $auth parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 27.09%
Affected Products (NVD)
VendorProductVersion
surrealdbsurrealdb
𝑥
< 1.5.4
surrealdbsurrealdb
2.0.0:alpha1
surrealdbsurrealdb
2.0.0:alpha2
surrealdbsurrealdb
2.0.0:alpha3
surrealdbsurrealdb
2.0.0:alpha4
surrealdbsurrealdb
2.0.0:alpha5
𝑥
= Vulnerable software versions