Описание
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic. Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject type is affected by this problem. The CheckPermission, BulkCheckPermission, and LookupSubjects API methods are affected. This vulnerability is fixed in 1.29.2.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.29.2 (исключая)
cpe:2.3:a:authzed:spicedb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00107
Низкий
7.3 High
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-190
Связанные уязвимости
CVSS3: 7.3
github
почти 2 года назад
Integer overflow in chunking helper causes dispatching to miss elements or panic
EPSS
Процентиль: 29%
0.00107
Низкий
7.3 High
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-190