Executive brief
SurrealDB is a multi-model database used for building applications with complex data relationships. A denial-of-service vulnerability allows privileged owner-level users to create system accounts with invalid role assignments. When another user attempts to sign in with such an invalid role, the database server crashes due to an unhandled error, making the database unavailable to legitimate users.
Technical details
The vulnerability exists in SurrealDB's identity and access management (IAM) layer, specifically in the From<&Ident> for Role trait implementation. Roles are stored as generic Ident values and converted to the Role enum during IAM operations. The conversion function expects only valid role values (owner, editor, viewer) but an unwrap() call on the result causes a panic if an invalid role is encountered. A privileged owner-level user can use DEFINE USER to create users with nonexistent roles; when the affected user signs in or performs operations requiring role validation, an unhandled exception crashes the server. The vulnerability requires owner-level privileges to exploit and affects versions before 2.1.0. Patches in version 2.1.0 and later reject invalid roles during user definition and handle nonexistent roles with proper error handling rather than panicking.
Affected products
- SurrealDB SurrealDB < 2.1.0
- SurrealDB surrealdb-core < 2.1.0
Timeline
- 2024-11-22: disclosed
- 2024-11-22: patched: Version 2.1.0 released with fix