Uncaught Exception Affecting surrealdb package, versions <1.2.0
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUST-SURREALDB-6276555
- published 25 Feb 2024
- disclosed 21 Feb 2024
- credit idofilus
How to fix?
Upgrade surrealdb
to version 1.2.0 or higher.
Overview
Affected versions of this package are vulnerable to Uncaught Exception in the query executor when executing a query containing a call to a nonexistent built-in function. This vulnerability can arise by mistake when the SurrealDB client version is newer than the SurrealDB server or when a pre-parsed query is provided to the server via a newer version of the SurrealDB SDK.
References
CVSS Scores
version 3.1