SurrealDB
- < 2.1.0
A denial-of-service vulnerability has been identified in SurrealDB versions prior to 2.1.0. The issue arises in the role conversion process, where privileged owner users can assign nonexistent roles to users. When a user with an invalid role attempts to sign in, it triggers an uncaught panic, causing the server to crash.
Exploitation of this vulnerability leads to an uncaught exception that causes the server to crash, creating a denial-of-service condition.
Users can update to SurrealDB version 2.1.0 or later, where this vulnerability has been patched. Affected users unable to update should limit access to the 'owner' role to trusted individuals and ensure that the SurrealDB process is running to automatically restart the server after a crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.