Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.5 Go

Dgraph Audit Log Encryption Vulnerability

GHSA-92wq-q9pq-gw47 · CVE-2023-31135

Published · Modified

Description

Impact

Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. All audit logs generated by versions of Dgraph <v23.0.0 are affected.

Patches

This issue was patched in https://github.com/dgraph-io/dgraph/pull/8323. Dgraph users should upgrade to v23.0.0.

Workarounds

Store existing audit logs in a secure location. For extra security, encrypt using a tool like gpg.

References

See https://github.com/dgraph-io/dgraph/pull/8323 for more context on the vulnerability.

Ready to move

Start Securing

Free, no credit card | First findings in minutes