PT-2024-33261 · Spicedb+1 · Spicedb+1

Vroldanbet

·

Published

2024-10-14

·

Updated

2024-11-05

·

CVE-2024-48909

CVSS v3.1

2.4

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SpiceDB versions 1.35.0 through 1.37.0
Description SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Clients that have enabled LookupResources2 and have caveats in the evaluation path for their requests can return a permissionship of CONDITIONAL with context marked as missing, even when the context was supplied. This issue occurs because LookupResources2 is the new default in SpiceDB 1.37.0 and has been opt-in since SpiceDB 1.35.0.
Recommendations For SpiceDB versions 1.35.0 through 1.37.0, disable LookupResources2 via the --enable-experimental-lookup-resources flag by setting it to false. For SpiceDB versions prior to 1.37.1, update to SpiceDB 1.37.1 to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-48909
GHSA-3C32-4HQ9-6WGJ
GO-2024-3200
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Spicedb
Suse