PT-2023-25388 · Spicedb · Spicedb

Lowecordell

·

Publicado

2023-06-26

·

Atualizado

2024-08-20

·

CVE-2023-35930

CVSS v3.1

3.7

Baixa

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SpiceDB version 1.22.0
Description The issue affects users making negative authorization decisions based on the results of a LookupResources request. This can lead to incorrect access control, where some subjects may not have access to resources they should, or some users may have access to resources they should not. The LookupResources function is not intended for gating access and should be used in conjunction with the Check API. Version 1.22.0 includes a warning about this bug. Users are advised to upgrade to version 1.22.2 to resolve the issue.
Recommendations For SpiceDB version 1.22.0, upgrade to version 1.22.2 to resolve the issue. If unable to upgrade, avoid using LookupResources for negative authorization decisions as a temporary workaround.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-35930
GHSA-M54H-5X5F-5M6R
GO-2023-1871

Produtos afetados

Spicedb