Vulnerabilities > CVE-2023-46255 - Unspecified vulnerability in Authzed Spicedb
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`) the full URI (including the provided password) is printed, so that the password is shown in the logs. Version 1.27.0-rc1 patches this issue.
Vulnerable Configurations
References
- https://github.com/authzed/spicedb/commit/ae50421b80f895e4c98d999b18e06b6f1e6f1cf8
- https://github.com/authzed/spicedb/commit/ae50421b80f895e4c98d999b18e06b6f1e6f1cf8
- https://github.com/authzed/spicedb/security/advisories/GHSA-jg7w-cxjv-98c2
- https://github.com/authzed/spicedb/security/advisories/GHSA-jg7w-cxjv-98c2