Логотип exploitDog
bind:CVE-2023-46255
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-46255

Количество 2

Количество 2

nvd логотип

CVE-2023-46255

больше 2 лет назад

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`) the full URI (including the provided password) is printed, so that the password is shown in the logs. Version 1.27.0-rc1 patches this issue.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-jg7w-cxjv-98c2

больше 2 лет назад

SpiceDB leaks information in log files when URI cannot be parsed

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-46255

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`) the full URI (including the provided password) is printed, so that the password is shown in the logs. Version 1.27.0-rc1 patches this issue.

CVSS3: 4.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-jg7w-cxjv-98c2

SpiceDB leaks information in log files when URI cannot be parsed

CVSS3: 4.2
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу