Описание
SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0.
A flaw was found in SpiceDB, an open-source database system for managing application permissions. This vulnerability occurs due to improper cache reuse when processing caveat structures that contain nested lists. This could lead to unexpected behavior or a low impact on confidentiality, potentially resulting in minor information disclosure.
Отчет
Red Hat ships SpiceDB as a dependency in the Management Platform service (cloud.redhat.com). The vulnerability involves improper cache reuse when processing caveat structures with nested lists, which could lead to minor information disclosure. The affected version range is 1.15.0 to before 1.52.0.
Меры по смягчению последствий
Avoid using caveat structures with nested lists in SpiceDB permission definitions until the fix (v1.52.0) is applied. Alternatively, update SpiceDB to version 1.52.0 or later.
Дополнительная информация
Статус:
4.3 Medium
CVSS3
Связанные уязвимости
SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0.
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
4.3 Medium
CVSS3