SpiceDB leaks information in log files when URI cannot be parsed
Package
Affected versions
< 1.27.0-rc1
Patched versions
1.27.0-rc1
Description
Published by the National Vulnerability Database
Oct 31, 2023
Published to the GitHub Advisory Database
Oct 31, 2023
Reviewed
Oct 31, 2023
Last updated
Nov 3, 2023
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. When the provided datastore URI is malformed (e.g. by having a password which contains
:
) the full URI (including the provided password) is printed, so that the password is shown in the logs. Version 1.27.0-rc1 patches this issue.Example output:
References