Skip to content
DgraphGHSA-92wq-q9pq-gw47

Dgraph Audit Log Encryption Vulnerability

Medium5.5CVE-2023-31135 · Published May 17, 2023 · updated Nov 8, 2023

### Impact Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. All audit logs generated by versions of Dgraph <v23.0.0 are affected. ### Patches This issue was patched in https://github.com/dgraph-io/dgraph/pull/8323. Dgraph users should upgrade to v23.0.0. ### Workarounds Store existing audit logs in a secure location. For extra security, encrypt using a tool like `gpg`. ### References See https://github.com/dgraph-io/dgraph/pull/8323 for more context on the vulnerability.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/dgraph-io/dgraph
Go
< 23.0.023.0.0
Details and references

More Dgraph advisories

All Dgraph

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.