Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2914 | SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for their requests can return a permissionship of `CONDITIONAL` with context marked as missing, even then the context was supplied. LookupResources2 is the new default in SpiceDB 1.37.0 and has been opt-in since SpiceDB 1.35.0. The bug is patched as part of SpiceDB 1.37.1. As a workaround, disable LookupResources2 via the `--enable-experimental-lookup-resources` flag by setting it to `false`. |
Github GHSA |
GHSA-3c32-4hq9-6wgj | SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not |
Thu, 17 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Authzed
Authzed spicedb |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:authzed:spicedb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Authzed
Authzed spicedb |
Tue, 15 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Oct 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for their requests can return a permissionship of `CONDITIONAL` with context marked as missing, even then the context was supplied. LookupResources2 is the new default in SpiceDB 1.37.0 and has been opt-in since SpiceDB 1.35.0. The bug is patched as part of SpiceDB 1.37.1. As a workaround, disable LookupResources2 via the `--enable-experimental-lookup-resources` flag by setting it to `false`. | |
| Title | SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not | |
| Weaknesses | CWE-172 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-15T14:45:43.494Z
Reserved: 2024-10-09T22:06:46.171Z
Link: CVE-2024-48909
Updated: 2024-10-15T14:45:38.216Z
Status : Analyzed
Published: 2024-10-14T21:15:12.080
Modified: 2024-10-17T17:56:11.130
Link: CVE-2024-48909
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA