SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph ed…
Medium CVSS 6.5
Summary
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-vjjx-rfw4-rmfc Vendor Advisory
- https://www.vulncheck.com/advisories/surrealdb-before-permission-bypass-via-graph-traversal Third Party Advisory
Timeline
- nvd_ingest NVD