Access Control Bypass Affecting github.com/authzed/spicedb/internal/graph package, versions >=1.3.0 <1.4.0
Threat Intelligence
EPSS
0.09% (40th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMAUTHZEDSPICEDBINTERNALGRAPH-2336173
- published 12 Jan 2022
- disclosed 12 Jan 2022
- credit Víctor Roldán Betancort
Introduced: 12 Jan 2022
CVE-2022-21646 Open this link in a new tabHow to fix?
Upgrade github.com/authzed/spicedb/internal/graph
to version 1.4.0 or higher.
Overview
Affected versions of this package are vulnerable to Access Control Bypass via the intersection
function of the Wildcard Relationship Handler
component.
References
CVSS Scores
version 3.1