VYPR

apk package

wolfi/spicedb

pkg:apk/wolfi/spicedb

Vulnerabilities (63)

  • CVE-2023-45283HigNov 9, 2023
    affected < 0fixed 0

    The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equivalent to a path beginning with \\?\. Paths with a \??\ prefix may be used to access arbitrary locations on the system. For example,

  • CVE-2023-46255MedOct 31, 2023
    affected < 1.33.0-r0fixed 1.33.0-r0

    SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.27.0-rc1, when the provided datastore URI is malformed (e.g. by having a password which contains `:`) the full URI (including the p

  • CVE-2023-29193HigApr 14, 2023
    affected < 1.33.0-r0fixed 1.33.0-r0

    SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a flag named `--grpc-preshared-key` which is used to protect the gRPC API from being accessed by unauthor

Page 4 of 4