漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
`SPICEDB_DATASTORE_CONN_URI` is leaked when URI cannot be parsed
Vulnerability Description
SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`) the full URI (including the provided password) is printed, so that the password is shown in the logs. Version 1.27.0-rc1 patches this issue.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
SpiceDB 日志信息泄露漏洞
Vulnerability Description
SpiceDB是受 Google Zanzibar 启发的细粒度权限数据库。 SpiceDB 1.27.0 之前版本存在日志信息泄露漏洞,该漏洞源于当 URI 无法解析时,SPICEDB_DATASTORE_CONN_URI`就会泄漏,在日志中显示密码。
CVSS Information
N/A
Vulnerability Type
N/A