CVE-2024-58363

SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical identifier exists, allowing unauthorized actions if permissions rely solely on the $auth parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
cpe:2.3:a:surrealdb:surrealdb:2.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:surrealdb:surrealdb:2.0.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:surrealdb:surrealdb:2.0.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:surrealdb:surrealdb:2.0.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:surrealdb:surrealdb:2.0.0:alpha5:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-18 14:17

Updated : 2026-08-12 18:37


NVD link : CVE-2024-58363

Mitre link : CVE-2024-58363

CVE.ORG link : CVE-2024-58363


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-287

Improper Authentication