CyberRota Analysis
AI-GeneratedSurrealDB versions prior to 1.5.5 and 2.0.0-beta before 2.0.0-beta.3 are vulnerable due to inadequate validation of objects in the signin and signup operations of the RPC API, allowing unauthenticated attackers to execute arbitrary subqueries. This vulnerability can lead to unauthorized access and manipulation of non-IAM resources within the database, posing a significant risk to data integrity and security. Organizations using affected versions should prioritize patching to mitigate potential exploitation by malicious actors.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a SIGNIN or SIGNUP query and the RPC API is exposed to untrusted users, an unauthenticated attacker can encode a binary object containing a subquery using the bincode serialization format and supply it in place of credentials. The subquery is then executed within the database owner's SIGNIN/SIGNUP query under a system user session with the editor role, allowing the attacker to select, create, update, and delete non-IAM resources (though not view the query results directly, and not affect IAM resources, which require the owner role).
Related CVEs
Other vulnerabilities affecting the same vendor(s)