CVE-2022-21646 affects SpiceDB, a security-critical permissions database, where a flaw in handling wildcard relationships within "exclusion" or "intersection" operations can lead to incorrect access decisions. This vulnerability, rated 8.1 HIGH, allows an authenticated attacker to bypass intended access restrictions, resulting in unauthorized access to resources (C:H/I:H). While no active exploitation or public exploit code is reported, the issue has garnered some community discussion and media coverage, indicating awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.0CPE matchmatch criteria | cpe:2.3:a:authzed:spicedb:1.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.