GHSA-27vq-hv74-7cqp: SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
(updated )
The OVERWRITE
clause of the DEFINE TABLE
statement would fail to overwrite data for tables that were defined with TYPE RELATION
. Since table definitions include the PERMISSIONS
clause, this failure would result in permissions not being overwritten as a result, which may potentially lead users to believe they have changed the table permissions when they have not.
References
Detect and mitigate GHSA-27vq-hv74-7cqp with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →