Intel

AIKIDO-2024-10368

surrealdb is vulnerable to Improper Authorization

Improper Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 25, 2024

71

High Risk

This Affects:

rustsurrealdb
0.0.1 - 2.0.3
Fixed in 2.0.4
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to improper authorization due to the order in which permissions are processed. This flaw allows an attacker without the necessary permissions to view field values or access the contents of statements, filters, and computations.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

surrealdb is vulnerable to Improper Authorization in versions 0.0.1 - 2.0.3.

How to fix this

Upgrade the surrealdb library to the patch version.