Vulnerability Description
SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization decision based on the results of a `LookupResources` request with 1.22.0 is affected. For example, using `LookupResources` to find a list of resources to allow access to be okay: some subjects that should have access to a resource may not. But if using `LookupResources` to find a list of banned resources instead, then some users that shouldn't have access may. Generally, `LookupResources` is not and should not be to gate access in this way - that's what the `Check` API is for. Additionally, version 1.22.0 has included a warning about this bug since its initial release. Users are advised to upgrade to version 1.22.2. Users unable to upgrade should avoid using `LookupResources` for negative authorization decisions.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Authzed | Spicedb | 1.22.0 |
Related Weaknesses (CWE)
References
- https://github.com/authzed/spicedb/pull/1397PatchVendor Advisory
- https://github.com/authzed/spicedb/security/advisories/GHSA-m54h-5x5f-5m6rPatchVendor Advisory
- https://github.com/authzed/spicedb/pull/1397PatchVendor Advisory
- https://github.com/authzed/spicedb/security/advisories/GHSA-m54h-5x5f-5m6rPatchVendor Advisory
FAQ
What is CVE-2023-35930?
CVE-2023-35930 is a vulnerability with a CVSS score of 3.7 (LOW). SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization decision based on the...
How severe is CVE-2023-35930?
CVE-2023-35930 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-35930?
Check the references section above for vendor advisories and patch information. Affected products include: Authzed Spicedb.