DirectorySecurity Advisories
Sign In
Security Advisories

CGA-vr2h-76xr-f9x3

Published

Last updated

https://images.chainguard.dev/security/CGA-vr2h-76xr-f9x3
Package

spicedb

Latest Update
Fixed
Fixed Version

1.33.0-r0

Aliases
  • CVE-2023-46255
  • GHSA-jg7w-cxjv-98c2

Severity

4.2

Medium

CVSS V3

Summary

SpiceDB leaks information in log files when URI cannot be parsed

Description

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. When the provided datastore URI is malformed (e.g. by having a password which contains :) the full URI (including the provided password) is printed, so that the password is shown in the logs. Version 1.27.0-rc1 patches this issue.

Example output:

terminated with errors error="unable to create migration driver for postgres: parse \"postgres://spicedb:<PASSWORD IN PLAINTEXT>": invalid port \"<PASSWORD IN PLAINTEXT>\" after host"

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images