SurrealDB Permissions Leak: Potential Data Exposure Risk
- Severity
- HIGH
- Affected component
- surrealdb (cargo)
- Affected versions
- >= 2.0.0, < 2.1.4 or >= 2.2.0, < 2.2.2 or < 2.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or < 2.0.5 or >= 2.1.0, < 2.1.5 or < 2.5.0 or >= 3.0.0-alpha.1, < 3.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 1.5.5 or >= 2.0.0-beta.1, < 2.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 1.1.0 or < 3.1.0 or < 3.1.0 or < 1.2.0 or < 3.1.4 or < 1.2.1 or < 2.0.4 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.4 or >= 2.0.0-alpha.1, < 2.0.0-alpha.6 or < 2.1.0 or >= 3.0.0, < 3.1.5 or < 3.1.5 or >= 3.1.0, < 3.1.5 or < 2.1.0 or < 1.1.1 or >= 3.0.0, < 3.1.5 or < 1.1.0 or < 2.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 1.1.1 or < 3.1.0 or < 3.1.0 or >= 2.0.0, < 2.0.4 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.0.1 or < 2.6.1 or >= 3.0.0-alpha.8, < 3.0.0-beta.3
- Patched version
- 3.1.4
SurrealDB is under investigation for a permissions leak that may allow unauthorized users to read array elements. This issue does not permit data modification or privilege escalation.
What happened
SurrealDB is reportedly affected by a permissions leak where record users can read array elements that should be hidden by element-level SELECT permissions. This vulnerability affects only record users and does not allow data modification or privilege escalation. The issue is under investigation and has not been exploited in the wild.
The affected versions of SurrealDB include a complex range of versions with multiple gaps and exclusions. The exact versions affected are detailed in the threat data provided. It is recommended to consult the primary sources for precise version information.
What to do about it
- Upgrade SurrealDB to version 3.1.4 or later to mitigate the permissions leak.
- Review your SurrealDB configuration and permissions settings to ensure they align with your security policies.
- Monitor the primary sources for updates on the vulnerability and any additional mitigation advice.
How 0Day would have caught this
surrealdb is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using SurrealDB versions >= 2.0.0, < 2.1.4 or >= 2.2.0, < 2.2.2 or < 2.1.5 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or < 2.0.5 or >= 2.1.0, < 2.1.5 or < 2.5.0 or >= 3.0.0-alpha.1, < 3.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.5 or >= 2.0.0-beta.1, < 2.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.1.0 or < 3.1.0 or < 3.1.0 or < 1.2.0 or < 3.1.4 or < 1.2.1 or < 2.0.4 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.4 or >= 2.0.0-alpha.1, < 2.0.0-alpha.6 or < 2.1.0 or >= 3.0.0, < 3.1.5 or < 3.1.5 or >= 3.1.0, < 3.1.5 or < 2.1.0 or < 1.1.1 or >= 3.0.0, < 3.1.5 or < 1.1.0 or < 2.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 1.1.1 or < 3.1.0 or < 3.1.0 or >= 2.0.0, < 2.0.4 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.0.1 or < 2.6.1 or >= 3.0.0-alpha.8, < 3.0.0-beta.3.
What should I do right now?
Upgrade SurrealDB to version 3.1.4 or later to mitigate the permissions leak. Review your SurrealDB configuration and permissions settings to ensure they align with your security policies. Monitor the primary sources for updates on the vulnerability and any additional mitigation advice.
Is this vulnerability being actively exploited?
There is no evidence that this vulnerability has been exploited in the wild.