In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade surrealdb-core
to version 2.1.0 or higher.
Affected versions of this package are vulnerable to Uncaught Exception via the rand::time
function. This is only exploitable by a client who is authorized to run queries in a SurrealDB server.
Affected users who are unable to update to the fixed version are advised to limit the ability of untrusted clients to run the rand::time
function in the affected versions of SurrealDB using security capabilities.
Additionally, SurrealDB administrators are advised to ensure that the SurrealDB process is running so that it can be automatically re-started after a crash.