Vulnerability Description
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Delskayn | Rquickjs | < 0.4.2 |
| Surrealdb | Surrealdb | < 1.1.1 |
Related Weaknesses (CWE)
References
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-q3gg-m8hr-h4x4Vendor Advisory
- https://www.vulncheck.com/advisories/surrealdb-before-format-string-via-scriptinThird Party Advisory
FAQ
What is CVE-2024-58366?
CVE-2024-58366 is a vulnerability with a CVSS score of 8.5 (HIGH). SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string seq...
How severe is CVE-2024-58366?
CVE-2024-58366 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-58366?
Check the references section above for vendor advisories and patch information. Affected products include: Delskayn Rquickjs, Surrealdb Surrealdb.