PT-2024-24352 · Spicedb · Spicedb

Lowecordell

·

Published

2024-04-10

·

Updated

2025-09-02

·

CVE-2024-32001

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SpiceDB versions prior to v1.30.1
Description The issue arises from the use of a specific relation form, relation folder: folder | folder#parent, combined with an arrow, such as folder->view, which can cause LookupSubjects to return only partial results. This occurs when the same subject type is used multiple times in a relation, and relationships exist for both subject types, along with the use of an arrow over the relation. Any user relying on LookupSubjects for negative authorization decisions with versions before v1.30.1 is affected.
Recommendations For versions prior to v1.30.1, update to version v1.30.1 to resolve the issue. As a temporary workaround, consider avoiding the use of LookupSubjects for negative authorization decisions and/or avoid using the broken schema.

Exploit

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-32001
GHSA-J85Q-46HG-36P2
GO-2024-2716

Affected Products

Spicedb