VDB
Sign up
MEDIUM5.5

GHSA-92wq-q9pq-gw47

Dgraph Audit Log Encryption Vulnerability

Quick fix

GHSA-92wq-q9pq-gw47 — github.com/dgraph-io/dgraph: upgrade to the fixed version with the command below.

go get github.com/dgraph-io/dgraph@v23.0.0

Details

### Impact Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. All audit logs generated by versions of Dgraph <v23.0.0 are affected.

### Patches This issue was patched in https://github.com/dgraph-io/dgraph/pull/8323. Dgraph users should upgrade to v23.0.0.

### Workarounds Store existing audit logs in a secure location. For extra security, encrypt using a tool like `gpg`.

### References See https://github.com/dgraph-io/dgraph/pull/8323 for more context on the vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/dgraph-io/dgraph
Introduced in: 0Fixed in: 23.0.0
Fixgo get github.com/dgraph-io/dgraph@v23.0.0

References