Skip to content

Dgraph Audit Log Encryption Vulnerability

Low
skrdgraph published GHSA-92wq-q9pq-gw47 May 17, 2023

Package

gomod Dgraph (Go)

Affected versions

< v23.0.0

Patched versions

v23.0.0

Description

Impact

Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. All audit logs generated by versions of Dgraph <v23.0.0 are affected.

Patches

This issue was patched in #8323. Dgraph users should upgrade to v23.0.0.

Workarounds

Store existing audit logs in a secure location. For extra security, encrypt using a tool like gpg.

References

See #8323 for more context on the vulnerability.

Severity

Low

CVE ID

CVE-2023-31135

Weaknesses

No CWEs

Credits