PT-2024-32323 · Spicedb · Spicedb

Tim-Mod

·

Published

2024-09-18

·

Updated

2024-09-25

·

CVE-2024-46989

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions spicedb versions prior to 1.35.3
Description The issue arises when multiple caveats are applied over the same indirect subject type on the same relation, potentially resulting in no permission being returned when permission is expected. This can occur if a resource has multiple groups, and each group is caveated. The CheckPermission API may return NO PERMISSION when PERMISSION is expected.
Recommendations For versions prior to 1.35.3, upgrade to release version 1.35.3 to address the issue. As a temporary workaround for users unable to upgrade, consider not using caveats or avoiding the use of caveats on an indirect subject type with multiple entries.

Exploit

Fix

Improper Privilege Management

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46989
GHSA-JHG6-6QRX-38MR
GO-2024-3131

Affected Products

Spicedb