DirectorySecurity Advisories
Sign In
Security Advisories

CGA-f822-vg76-v76h

Published

Last updated

https://images.chainguard.dev/security/CGA-f822-vg76-v76h
Package

spicedb

Latest Update
Fixed
Fixed Version

1.30.0-r0

Aliases
  • GHSA-7jwh-3vrq-q3m8

Severity

9.8

Critical

CVSS V3

Summary

pgproto3 SQL Injection via Protocol Message Size Overflow

Description

Impact

SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control.

Patches

The problem is resolved in v2.3.3

Workarounds

Reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images