Dgraph Audit Log Encryption Vulnerability
Moderate severity
GitHub Reviewed
Published
May 17, 2023
in
hypermodeinc/dgraph
•
Updated Nov 7, 2023
Package
Affected versions
< 23.0.0
Patched versions
23.0.0
Description
Published to the GitHub Advisory Database
May 17, 2023
Reviewed
May 17, 2023
Published by the National Vulnerability Database
May 17, 2023
Last updated
Nov 7, 2023
Impact
Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. All audit logs generated by versions of Dgraph <v23.0.0 are affected.
Patches
This issue was patched in hypermodeinc/dgraph#8323. Dgraph users should upgrade to v23.0.0.
Workarounds
Store existing audit logs in a secure location. For extra security, encrypt using a tool like
gpg
.References
See hypermodeinc/dgraph#8323 for more context on the vulnerability.
References