CVE-2025-65111
- EPSS 0.06%
- Veröffentlicht 21.11.2025 22:02:52
- Zuletzt bearbeitet 25.11.2025 22:16:42
SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union refe...
CVE-2025-64529
- EPSS 0.06%
- Veröffentlicht 10.11.2025 22:28:51
- Zuletzt bearbeitet 21.11.2025 13:35:52
SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator somewhere in their authorization schema; have configured their SpiceDB se...
CVE-2025-49011
- EPSS 0.03%
- Veröffentlicht 06.06.2025 17:36:21
- Zuletzt bearbeitet 04.09.2025 16:48:00
SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the e...
CVE-2024-48909
- EPSS 0.08%
- Veröffentlicht 14.10.2024 21:15:12
- Zuletzt bearbeitet 17.10.2024 17:56:11
SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for the...
CVE-2024-46989
- EPSS 0.13%
- Veröffentlicht 18.09.2024 18:15:07
- Zuletzt bearbeitet 04.09.2025 16:41:18
spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can result in no permission being retur...
CVE-2024-38361
- EPSS 0.19%
- Veröffentlicht 20.06.2024 23:15:52
- Zuletzt bearbeitet 02.09.2025 20:37:12
Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources may resolve to `NO_PERMISSION` when permission is ...
CVE-2024-32001
- EPSS 0.14%
- Veröffentlicht 10.04.2024 23:15:07
- Zuletzt bearbeitet 02.09.2025 19:25:00
SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form: `relation folder: folder | folder#parent` with an arrow such as `folder->view` can cause LookupSubjects to only return the subjec...
CVE-2024-27101
- EPSS 0.11%
- Veröffentlicht 01.03.2024 21:15:08
- Zuletzt bearbeitet 02.09.2025 21:42:21
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic. Any SpiceDB cluster with any schema w...
CVE-2023-46255
- EPSS 0.16%
- Veröffentlicht 31.10.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:28:10
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`)...
CVE-2023-35930
- EPSS 0.13%
- Veröffentlicht 26.06.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 08:08:59
SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. Any user making a negative authorization decision based on the results of a `LookupResources` request with 1.22....