From 52364ae67d87eef328fdd57d704977a37f6eab7d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 10 Apr 2025 21:07:10 +0000 Subject: [PATCH] Publish GHSA-rq86-9m6r-cm3g --- .../GHSA-rq86-9m6r-cm3g.json | 97 +++++++++++++++++++ 1 file changed, 97 insertions(+) create mode 100644 advisories/github-reviewed/2025/04/GHSA-rq86-9m6r-cm3g/GHSA-rq86-9m6r-cm3g.json diff --git a/advisories/github-reviewed/2025/04/GHSA-rq86-9m6r-cm3g/GHSA-rq86-9m6r-cm3g.json b/advisories/github-reviewed/2025/04/GHSA-rq86-9m6r-cm3g/GHSA-rq86-9m6r-cm3g.json new file mode 100644 index 00000000000..e5f2daf0493 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-rq86-9m6r-cm3g/GHSA-rq86-9m6r-cm3g.json @@ -0,0 +1,97 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq86-9m6r-cm3g", + "modified": "2025-04-10T21:05:35Z", + "published": "2025-04-10T21:05:34Z", + "aliases": [], + "summary": "SurrealDB has uncaught exception in Net module that leads to database crash", + "details": "A vulnerability was found where an attacker can crash the database via crafting a HTTP query that returns a null byte. The problem relies on an uncaught exception in the `net` module, where the result of the query will be converted to JSON before showing as the HTTP response to the user in the **/sql** endpoint.\n\n### Impact\nThis vulnerability allows any authenticated user to crash a SurrealDB instance by sending a crafted query with a null byte to the /sql endpoint. \n\nWhere SurrealDB is used as an application backend, it is possible that an application user can crash the SurrealDB instance and thus the supported application through crafted inputs that exploit this attack vector.\n\n\n### Patches\nA patch has been introduced that ensures the error is caught and converted as an error.\n- Versions 2.2.2, 2.1.5 and 2.0.5 and later are not affected by this isssue\n\n### Workarounds\n\nAffected users who are unable to update may want to limit the ability of untrusted clients to run arbitrary queries in the affected versions of SurrealDB. To limit the impact of the denial of service, SurrealDB administrators may also want to ensure that the SurrealDB process is running so that it can be automatically re-started after a crash.\n\nWhere SurrealDB is used as an application backend, ensure sanitisation of input at the application layer to prevent injection attacks.\n\n### References\nhttps://github.com/surrealdb/surrealdb/pull/5647", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "crates.io", + "name": "surrealdb" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.2.0" + }, + { + "fixed": "2.2.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "surrealdb" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.1.0" + }, + { + "fixed": "2.1.5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "surrealdb" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.0.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-rq86-9m6r-cm3g" + }, + { + "type": "WEB", + "url": "https://github.com/surrealdb/surrealdb/pull/5647" + }, + { + "type": "PACKAGE", + "url": "https://github.com/surrealdb/surrealdb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-04-10T21:05:34Z", + "nvd_published_at": null + } +} \ No newline at end of file