CVE-2025-11060
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/09/2025
Última modificación:
26/09/2025
Descripción
*** Pendiente de traducción *** A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records.
Impacto
Puntuación base 3.x
5.70
Gravedad 3.x
MEDIA
Referencias a soluciones, herramientas e información
- https://access.redhat.com/security/cve/CVE-2025-11060
- https://bugzilla.redhat.com/show_bug.cgi?id=2394708
- https://github.com/surrealdb/surrealdb
- https://github.com/surrealdb/surrealdb/commit/d81169a06b89f0c588134ddf2d62eeb8d5e8fd0c
- https://github.com/surrealdb/surrealdb/pull/6247
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-7vm2-j586-vcvc
- https://surrealdb.com/docs/surrealql/statements/live



