CVE-2024-58356
Last modified
CVE-2024-58356 is a low-severity vulnerability rated 2.3/10 on the CVSS scale. SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table definitions include the PERMISSIONS clause, an attempt to tighten a table's permissions via OVERWRITE does not take effect, and the administrator may incorrectly believe the change was applied. As a result, a client authorized to run queries may continue to access data in that table that the updated (but unapplied) permissions were intended to restrict.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| surrealdb | surrealdb | < 2.1.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2024-58356?
How severe is CVE-2024-58356?
How do I fix CVE-2024-58356?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-58350Ghidra before 11.2 contains a use after free vulnerability i…4
- CVE-2024-58351Flowise before 2.1.4 allows configuration to be injected int…9.8
- CVE-2024-58352Landray OA contains an unauthenticated HQL injection vulnera…8.7
- CVE-2024-58353Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is…9.3
- CVE-2024-58354cal.com (calcom repository, later renamed cal.diy) is affect…9.9
- CVE-2024-58355Cal.com (calcom/cal.diy) versions through 4.7.15 contain a s…9.3
- CVE-2024-58357SurrealDB versions before 2.1.0 contain an uncaught exceptio…7.1
- CVE-2024-58358SurrealDB versions before 2.1.0 contain a denial of service …6.9
- CVE-2024-58359SurrealDB versions before 2.1.0 contain a denial of service …7.1
- CVE-2024-5836Inappropriate Implementation in DevTools in Google Chrome pr…8.8
- CVE-2024-58360stoatchat versions before 0.7.8 fail to enforce account crea…6.9
- CVE-2024-58361SurrealDB versions before 2.0.4 contain an uncaught exceptio…7.1
Are you affected by CVE-2024-58356?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
