CVE-2023-35930
CVSS V2 None
CVSS V3 None
Description
SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization decision based on the results of a `LookupResources` request with 1.22.0 is affected. For example, using `LookupResources` to find a list of resources to allow access to be okay: some subjects that should have access to a resource may not. But if using `LookupResources` to find a list of banned resources instead, then some users that shouldn't have access may. Generally, `LookupResources` is not and should not be to gate access in this way - that's what the `Check` API is for. Additionally, version 1.22.0 has included a warning about this bug since its initial release. Users are advised to upgrade to version 1.22.2. Users unable to upgrade should avoid using `LookupResources` for negative authorization decisions.
Overview
- CVE ID
- CVE-2023-35930
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-06-26T19:32:59.829Z
- Last Modified Date
- 2023-06-26T19:32:59.829Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/authzed/spicedb/security/advisories/GHSA-m54h-5x5f-5m6r | x_refsource_CONFIRM |
https://github.com/authzed/spicedb/pull/1397 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-35930 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35930 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 19:52:33 | Added to TrackCVE |