PT-2023-25388 · Spicedb · Spicedb

Lowecordell

·

Published

2023-06-26

·

Updated

2024-08-20

·

CVE-2023-35930

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SpiceDB version 1.22.0
Description The issue affects users making negative authorization decisions based on the results of a LookupResources request. This can lead to incorrect access control, where some subjects may not have access to resources they should, or some users may have access to resources they should not. The LookupResources function is not intended for gating access and should be used in conjunction with the Check API. Version 1.22.0 includes a warning about this bug. Users are advised to upgrade to version 1.22.2 to resolve the issue.
Recommendations For SpiceDB version 1.22.0, upgrade to version 1.22.2 to resolve the issue. If unable to upgrade, avoid using LookupResources for negative authorization decisions as a temporary workaround.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-35930
GHSA-M54H-5X5F-5M6R
GO-2023-1871

Affected Products

Spicedb