PT-2024-33261 · Spicedb+1 · Spicedb+1
Vroldanbet
·
Published
2024-10-14
·
Updated
2024-11-05
·
CVE-2024-48909
CVSS v3.1
2.4
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SpiceDB versions 1.35.0 through 1.37.0
Description
SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Clients that have enabled
LookupResources2 and have caveats in the evaluation path for their requests can return a permissionship of CONDITIONAL with context marked as missing, even when the context was supplied. This issue occurs because LookupResources2 is the new default in SpiceDB 1.37.0 and has been opt-in since SpiceDB 1.35.0.Recommendations
For SpiceDB versions 1.35.0 through 1.37.0, disable
LookupResources2 via the --enable-experimental-lookup-resources flag by setting it to false.
For SpiceDB versions prior to 1.37.1, update to SpiceDB 1.37.1 to resolve the issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spicedb
Suse