Integer Overflow or Wraparound Affecting github.com/authzed/spicedb/pkg/genutil/slicez package, versions <1.29.2


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMAUTHZEDSPICEDBPKGGENUTILSLICEZ-6356279
  • published3 Mar 2024
  • disclosed1 Mar 2024
  • creditUnknown

Introduced: 1 Mar 2024

CVE-2024-27101  (opens in a new tab)
CWE-190  (opens in a new tab)

How to fix?

Upgrade github.com/authzed/spicedb/pkg/genutil/slicez to version 1.29.2 or higher.

Overview

github.com/authzed/spicedb/pkg/genutil/slicez is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained access control for customer applications

Affected versions of this package are vulnerable to Integer Overflow or Wraparound in the chunking helper, which causes dispatching to miss elements. If a resource being checked has more than 65535 relationships for the same resource and subject type the CheckPermission, BulkCheckPermission, and LookupSubjects API methods can be manipulated to allow operations that should be blocked or cause a panic.

References

CVSS Base Scores

version 3.1