CVE-2024-48909

CVSS 3.1 Score 2.4 of 10 (low)

Details

Published Oct 14, 2024
Updated: Oct 17, 2024
CWE ID 172

Summary

CVE-2024-48909 is a vulnerability affecting SpiceDB, an open-source database used for storing and querying fine-grained authorization data. In versions 1.35.0 and prior to 1.37.1, clients with `LookupResources2` enabled and specific caveats in their requests can receive a misleading permissions result, indicating a conditionally granted access with missing context. However, the context was actually provided. LookupResources2 is the new default since version 1.37.0 and has been opt-in since version 1.35.0. A patch addressing this issue is available in SpiceDB 1.37.1. A temporary workaround includes disabling LookupResources2 using the `--enable-experimental-lookup-resources` flag set to `false`.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share