
Cloud Vulnerability DB
A community-led vulnerabilities database
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. An integer overflow vulnerability (CVE-2024-27101) was discovered in the chunking helper that causes dispatching to miss elements or panic. The vulnerability affects any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject type. This vulnerability was disclosed on March 1, 2024, and has been fixed in version 1.29.2 (GitHub Advisory).
The vulnerability is caused by an integer overflow in the chunking helper functionality. The issue affects the CheckPermission, BulkCheckPermission, and LookupSubjects API methods. The vulnerability has been assigned a CVSS v3.1 base score of 7.3 (High) with the vector string CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:H, indicating network attack vector, high attack complexity, high privileges required, user interaction required, changed scope, and high impact on integrity and availability (GitHub Advisory).
The vulnerability can cause permission checks that are expected to be allowed to be denied instead, and lookup subjects will return fewer subjects than expected. Additionally, the issue may lead to a panic rendering the server unavailable (GitHub Advisory).
The vulnerability requires high attack complexity and high privileges to exploit. User interaction is required, and the attack vector is network-based (GitHub Advisory).
There is no workaround other than ensuring that the SpiceDB cluster does not have very wide relations, with the maximum value being the maximum value of a 16-bit unsigned integer. AuthZed Dedicated and Serverless customers require no action as AuthZed has upgraded all deployments. AuthZed Enterprise customers should upgrade to v1.29.2-hotfix-enterprise.v1.hotfix.v1, while Open Source users should upgrade to v1.29.2 (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."