github.com
https://github.com/authzed/spicedb CVE-2024-27101
HIGH
Integer overflow in chunking helper causes dispatching to miss elements or panic
Record summary
CVE-2024-27101 has a selected CVSS score of 7.3 (high).
Description
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic. Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject type is affected by this problem. The CheckPermission, BulkCheckPermission, and LookupSubjects API methods are affected. This vulnerability is fixed in 1.29.2.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 6, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
spicedbBrowse authzed / spicedb | CVE List | < 1.29.2 | affected |
github.com/authzed/spicedbBrowse Go / github.com/authzed/spicedb | GitHub Advisory | Before 1.29.2 · Fixed in 1.29.2 | affected |
References
4github.com
https://github.com/authzed/spicedb/commit/ef443c442b96909694390324a99849b0407007fe github.comConfirmation
https://github.com/authzed/spicedb/security/advisories/GHSA-h3m7-rqc4-7h9p nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-27101