Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-48909

Опубликовано: 14 окт. 2024
Источник: nvd
CVSS3: 2
CVSS3: 2.4
EPSS Низкий

Описание

SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled LookupResources2 and have caveats in the evaluation path for their requests can return a permissionship of CONDITIONAL with context marked as missing, even then the context was supplied. LookupResources2 is the new default in SpiceDB 1.37.0 and has been opt-in since SpiceDB 1.35.0. The bug is patched as part of SpiceDB 1.37.1. As a workaround, disable LookupResources2 via the --enable-experimental-lookup-resources flag by setting it to false.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:authzed:spicedb:*:*:*:*:*:*:*:*
Версия от 1.35.0 (включая) до 1.37.1 (исключая)

EPSS

Процентиль: 24%
0.00084
Низкий

2 Low

CVSS3

2.4 Low

CVSS3

Дефекты

CWE-172
NVD-CWE-Other

Связанные уязвимости

CVSS3: 2
github
больше 1 года назад

SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not

suse-cvrf
больше 1 года назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 24%
0.00084
Низкий

2 Low

CVSS3

2.4 Low

CVSS3

Дефекты

CWE-172
NVD-CWE-Other