PT-2024-33261 · Spicedb+1 · Spicedb+1

·

CVE-2024-48909

·

Published

2024-10-14

·

Updated

2024-11-05

CVSS v3.1

2.4

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SpiceDB versions 1.35.0 through 1.37.0
Description SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Clients that have enabled LookupResources2 and have caveats in the evaluation path for their requests can return a permissionship of CONDITIONAL with context marked as missing, even when the context was supplied. This issue occurs because LookupResources2 is the new default in SpiceDB 1.37.0 and has been opt-in since SpiceDB 1.35.0.
Recommendations For SpiceDB versions 1.35.0 through 1.37.0, disable LookupResources2 via the --enable-experimental-lookup-resources flag by setting it to false. For SpiceDB versions prior to 1.37.1, update to SpiceDB 1.37.1 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48909
GHSA-3C32-4HQ9-6WGJ
GO-2024-3200
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Spicedb
Suse