VDB

CVE-2023-46255

CVE-2023-46255 PUBLISHED CVSS 4.199999809265137 MEDIUM

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`) the full URI (including the provided password) is printed, so that the password is shown in the logs. Version 1.27.0-rc1 patches this issue.

EPSS 0.17% · 38.4th percentile

Risk Scores

CVSS v3.1
4.199999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.17%
38.4th percentile

Affected Products

VendorProductVersions
github.comauthzed/spicedb0, 0
authzedspicedb< 1.27.0-rc1, 0, < 1.27.0-rc1

Timeline

  • Oct 31, 2023 CVE Published
  • Oct 31, 2023 PoC Published
  • Nov 1, 2023 EPSS Score
  • Dec 2, 2023 EPSS Score
  • Jan 1, 2024 EPSS Score
  • Feb 1, 2024 EPSS Score
  • Mar 3, 2024 EPSS Score
  • Apr 2, 2024 EPSS Score
  • May 3, 2024 EPSS Score
  • Jun 3, 2024 EPSS Score
  • Jul 3, 2024 EPSS Score
  • Aug 3, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›