CVE-2025-11060
⚪ Do wiadomości
Błąd w mechanizmie subskrypcji zapytań na żywo w silniku bazy danych umożliwia nieautoryzowany dostęp do rekordów.
CVSS
5.7
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-09-26 13:15:41 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 10:10:00 UTC |
Referencje
- https://access.redhat.com/security/cve/CVE-2025-11060 ([email protected])
- https://bugzilla.redhat.com/show_bug.cgi?id=2394708 ([email protected])
- https://github.com/surrealdb/surrealdb ([email protected])
- https://github.com/surrealdb/surrealdb/commit/d81169a06b89f0c588134ddf2d62eeb8d5e8fd0c ([email protected])
- https://github.com/surrealdb/surrealdb/pull/6247 ([email protected])
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-7vm2-j586-vcvc ([email protected])
- https://surrealdb.com/docs/surrealql/statements/live ([email protected])