Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7p8f-8hjm-wm92

Опубликовано: 13 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Lookup operations do not take into account wildcards in SpiceDB

Impact

Any user making use of a wildcard relationship under the right hand branch of an exclusion or within an intersection operation will see Lookup/LookupResources return a resource as "accessible" if it is not accessible by virtue of the inclusion of the wildcard in the intersection or the right side of the exclusion.

For example, given schema:

definition user {} definition resource { relation viewer: user relation banned: user | user:* permission view = viewer - banned }

If user:* is placed into the banned relation for a particular resource, view should return false for all resources. in v1.3.0, the wildcard is ignored entirely in lookup's dispatch, resulting in the banned wildcard being ignored in the exclusion.

Workarounds

Don't make use of wildcards on the right side of intersections or within exclusions.

References

https://github.com/authzed/spicedb/issues/358

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

github.com/authzed/spicedb

go
Затронутые версииВерсия исправления

= 1.3.0

1.4.0

EPSS

Процентиль: 56%
0.00343
Низкий

8.1 High

CVSS3

Дефекты

CWE-155
CWE-20

Связанные уязвимости

CVSS3: 8.1
nvd
около 4 лет назад

SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation will see `Lookup`/`LookupResources` return a resource as "accessible" if it is *not* accessible by virtue of the inclusion of the wildcard in the intersection or the right side of the exclusion. In `v1.3.0`, the wildcard is ignored entirely in lookup's dispatch, resulting in the `banned` wildcard being ignored in the exclusion. Version 1.4.0 contains a patch for this issue. As a workaround, don't make use of wildcards on the right side of intersections or within exclusions.

EPSS

Процентиль: 56%
0.00343
Низкий

8.1 High

CVSS3

Дефекты

CWE-155
CWE-20