CVE-2023-31135 describes a brute-force vulnerability in Dgraph's audit logs, affecting all versions prior to v23.0.0. The flaw stems from nonce collisions during encryption, where the reuse of nonces due to predictable log line lengths makes the logs susceptible to decryption. This vulnerability has a CVSS score of 5.5 (Medium), indicating that an attacker with local access to the system storing the logs could potentially compromise the confidentiality of the audit data. While there are no known active exploits, public exploit code, or significant community discussion, users are advised to upgrade to Dgraph v23.0.0 or encrypt existing logs externally as a mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.0.0CPE matchmatch criteria | cpe:2.3:a:dgraph:dgraph:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.