SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through err…
Medium CVSS 4.3
Summary
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden fields to embed raw operand values in error responses, bypassing field-level access controls.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-6g9v-7gq3-p2c6 Vendor Advisory
- https://www.vulncheck.com/advisories/surrealdb-before-information-disclosure-via-error-messages Third Party Advisory
Timeline
- nvd_ingest NVD