CyberRota Analysis
AI-GeneratedSurrealDB versions prior to 3.2.0 are vulnerable due to inadequate validation of namespace and database scope in custom API routes, enabling authenticated users to access endpoints across different namespaces/databases. This flaw allows attackers with valid credentials to read sensitive data or execute unintended operations by manipulating the URL path. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data access and potential operational disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials for any namespace/database can access custom API endpoints in other tenants by specifying the target scope in the URL path, reading sensitive data or triggering unintended operations.
Related CVEs
Other vulnerabilities affecting the same vendor(s)