CyberRota Analysis
AI-GeneratedSurrealDB versions prior to 3.1.0 are vulnerable due to a failure to refresh authentication state in LIVE SELECT subscriptions, allowing attackers to receive real-time notifications even after their session credentials have been revoked or expired. This could lead to unauthorized access to sensitive data, posing a risk to data confidentiality. Organizations using affected versions should prioritize this vulnerability to mitigate potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.
Related CVEs
Other vulnerabilities affecting the same vendor(s)