SCA: security update for github.com/authzed/spicedb (GHSA-jhg6-6qrx-38mr)

medium Tenable Cloud Security Plugin ID 416388

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained
authorization for customer applications. Multiple caveats over the same indirect subject type on the same
relation can result in no permission being returned when permission is expected. If the resource has
multiple groups, and each group is caveated, it is possible for the returned permission to be "no
permission" when permission is expected. Permission is returned as NO_PERMISSION when PERMISSION is
expected on the CheckPermission API. This issue has been addressed in release version 1.35.3. Users are
advised to upgrade. Users unable to upgrade should not use caveats or avoid the use of caveats on an
indirect subject type with multiple entries. (CVE-2024-46989)

See Also

https://github.com/advisories/GHSA-jhg6-6qrx-38mr

Plugin Details

Severity: Medium

ID: 416388

Version: Revision 1.11

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2024-46989

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 1.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/18/2024

Vulnerability Publication Date: 9/18/2024

Reference Information

CVE: CVE-2024-46989