You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
Spicedb is an Open Source, Google Zanzibar-inspired permissions database to
enable fine-grained authorization for customer applications. Use of an exclusion
under an arrow that has multiple resources may resolve to NO_PERMISSION when
permission is expected. If the resource exists under multiple folders and the
user has access to view more than a single folder, SpiceDB may report the user
does not have access due to a failure in the exclusion dispatcher to request
that all the folders in which the user is a member be returned. Permission is
returned as NO_PERMISSION when PERMISSION is...
Advisory CVE-2024-38361 references a vulnerability in the following Go modules:
Description:
Spicedb is an Open Source, Google Zanzibar-inspired permissions database to
enable fine-grained authorization for customer applications. Use of an exclusion
under an arrow that has multiple resources may resolve to
NO_PERMISSION
whenpermission is expected. If the resource exists under multiple folders and the
user has access to view more than a single folder, SpiceDB may report the user
does not have access due to a failure in the exclusion dispatcher to request
that all the folders in which the user is a member be returned. Permission is
returned as
NO_PERMISSION
whenPERMISSION
is...References:
Cross references:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: