PT-2022-15001 · Spicedb · Spicedb

Vroldanbet

·

Published

2022-01-11

·

Updated

2024-08-21

·

CVE-2022-21646

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SpiceDB versions 1.3.0
Description The issue concerns the handling of wildcard relationships in SpiceDB, specifically within exclusion or intersection operations. When a user utilizes a wildcard relationship under the right-hand branch of an exclusion or within an intersection operation, the Lookup/LookupResources function may return a resource as "accessible" even if it is not accessible due to the inclusion of the wildcard. This occurs because the wildcard is ignored entirely in lookup's dispatch in version 1.3.0, resulting in the banned wildcard being ignored in the exclusion.
Recommendations For version 1.3.0, update to version 1.4.0 to resolve the issue. As a temporary workaround, do not make use of wildcards on the right side of intersections or within exclusions.

Exploit

Fix

RCE

Improper Neutralization of Wildcards

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21646
GHSA-7P8F-8HJM-WM92
GO-2022-0295

Affected Products

Spicedb