HIGH · 8.5

CVE-2024-58366

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string seq...

Vulnerability Description

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.

CVSS Score

8.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DelskaynRquickjs< 0.4.2
SurrealdbSurrealdb< 1.1.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-58366?

CVE-2024-58366 is a vulnerability with a CVSS score of 8.5 (HIGH). SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string seq...

How severe is CVE-2024-58366?

CVE-2024-58366 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-58366?

Check the references section above for vendor advisories and patch information. Affected products include: Delskayn Rquickjs, Surrealdb Surrealdb.