{"id":"GHSA-27vq-hv74-7cqp","summary":"SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type","details":"The `OVERWRITE` clause of the `DEFINE TABLE` statement would fail to overwrite data for tables that were defined with `TYPE RELATION`. Since table definitions include the `PERMISSIONS` clause, this failure would result in permissions not being overwritten as a result, which may potentially lead users to believe they have changed the table permissions when they have not.\n\n### Impact\n\nIf a user attempted to update table permissions of a table defined with `TYPE RELATION` using `DEFINE TABLE ... OVERWRITE`, permissions for the table would not be changed. This may allow a client that is authorized to run queries in a SurrealDB server to access certain data in that specific table that they were not intended to be able to access after the specified change in permissions.\n\n### Patches\n\nThe `DEFINE TABLE` statement has been updated to appropriately overwrite data for tables defined with `TYPE RELATION`.\n\n- Version 2.1.4 and later are not affected by this issue.\n\n### Workarounds\n\nUsers of tables with `TYPE RELATION` that may have been modified using the `OVERWRITE` clause in order to update permissions are advised to verify that the intended permissions are in place using the `INFO FOR DB` statement. Affected users who are unable to update and require updating permissions in a table with `TYPE RELATION` will be required to remove the table and define it from scratch with the intended permissions. Data can be preserved by backing it up to a temporary table.\n\n### References\n\n- [#5260](https://github.com/surrealdb/surrealdb/pull/5260)","aliases":["CVE-2024-58356"],"modified":"2026-09-04T19:00:05.430424412Z","published":"2024-12-16T17:38:53Z","database_specific":{"cwe_ids":["CWE-732"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2024-12-16T17:38:53Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/surrealdb/surrealdb/security/advisories/GHSA-27vq-hv74-7cqp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-58356"},{"type":"WEB","url":"https://github.com/surrealdb/surrealdb/pull/5260"},{"type":"WEB","url":"https://github.com/surrealdb/surrealdb/commit/2f9a58f830c24f107b4783da1f0704a502bc7734"},{"type":"PACKAGE","url":"https://github.com/surrealdb/surrealdb"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/surrealdb-before-permission-bypass-via-define-table-overwrite"}],"affected":[{"package":{"name":"surrealdb","ecosystem":"crates.io","purl":"pkg:cargo/surrealdb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-27vq-hv74-7cqp/GHSA-27vq-hv74-7cqp.json"}},{"package":{"name":"surrealdb-core","ecosystem":"crates.io","purl":"pkg:cargo/surrealdb-core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-27vq-hv74-7cqp/GHSA-27vq-hv74-7cqp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}