GHSA-9567-jfw6-h5pcMediumCVSS 4.3
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when...
🔗 CVE IDs covered (1)
📋 Description
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.