MEDIUM5.5
GHSA-92wq-q9pq-gw47
Dgraph Audit Log Encryption Vulnerability
Quick fix
GHSA-92wq-q9pq-gw47 — github.com/dgraph-io/dgraph: upgrade to the fixed version with the command below.
go get github.com/dgraph-io/dgraph@v23.0.0Details
### Impact Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. All audit logs generated by versions of Dgraph <v23.0.0 are affected.
### Patches This issue was patched in https://github.com/dgraph-io/dgraph/pull/8323. Dgraph users should upgrade to v23.0.0.
### Workarounds Store existing audit logs in a secure location. For extra security, encrypt using a tool like `gpg`.
### References See https://github.com/dgraph-io/dgraph/pull/8323 for more context on the vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/dgraph-io/dgraph
Introduced in:
0Fixed in: 23.0.0Fix
go get github.com/dgraph-io/dgraph@v23.0.0References
- https://github.com/dgraph-io/dgraph/security/advisories/GHSA-92wq-q9pq-gw47[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-31135[ADVISORY]
- https://github.com/dgraph-io/dgraph/pull/8323[WEB]
- https://en.wikipedia.org/wiki/Cryptographic_nonce[WEB]
- https://github.com/dgraph-io/dgraph[PACKAGE]
- https://github.com/dgraph-io/dgraph/releases/tag/v23.0.0[WEB]