PT-2023-25388 · Spicedb · Spicedb
Lowecordell
·
Published
2023-06-26
·
Updated
2024-08-20
·
CVE-2023-35930
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SpiceDB version 1.22.0
Description
The issue affects users making negative authorization decisions based on the results of a
LookupResources request. This can lead to incorrect access control, where some subjects may not have access to resources they should, or some users may have access to resources they should not. The LookupResources function is not intended for gating access and should be used in conjunction with the Check API. Version 1.22.0 includes a warning about this bug. Users are advised to upgrade to version 1.22.2 to resolve the issue.Recommendations
For SpiceDB version 1.22.0, upgrade to version 1.22.2 to resolve the issue. If unable to upgrade, avoid using
LookupResources for negative authorization decisions as a temporary workaround.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spicedb