CVE-2024-32001

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-32001
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32001.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-32001
Aliases
Related
Published
2024-04-10T22:25:12Z
Modified
2025-10-21T19:32:50Z
Severity
  • 2.2 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
SpiceDB: LookupSubjects may return partial results if a specific kind of relation is used
Details

SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form: relation folder: folder | folder#parent with an arrow such as folder->view can cause LookupSubjects to only return the subjects found under subjects for either folder or folder#parent. This bug only manifests if the same subject type is used multiple types in a relation, relationships exist for both subject types and an arrow is used over the relation. Any user making a negative authorization decision based on the results of a LookupSubjects request with version before v1.30.1 is affected. Version 1.30.1 contains a patch for the issue. As a workaround, avoid using LookupSubjects for negative authorization decisions and/or avoid using the broken schema.

Database specific
{
    "cwe_ids": [
        "CWE-755"
    ]
}
References

Affected packages

Git / github.com/authzed/spicedb

Affected ranges

Type
GIT
Repo
https://github.com/authzed/spicedb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed