Dgraph Audit Log Encryption Vulnerability
Description
Published to the GitHub Advisory Database
May 17, 2023
Reviewed
May 17, 2023
Published by the National Vulnerability Database
May 17, 2023
Last updated
Nov 7, 2023
Impact
Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. All audit logs generated by versions of Dgraph <v23.0.0 are affected.
Patches
This issue was patched in dgraph-io/dgraph#8323. Dgraph users should upgrade to v23.0.0.
Workarounds
Store existing audit logs in a secure location. For extra security, encrypt using a tool like
gpg
.References
See dgraph-io/dgraph#8323 for more context on the vulnerability.
References