github.com/weaviate/weaviate is vulnerable to Race Condition
55
Medium Risk
Affected versions of this package are affected by a race condition when creating roles that can lead to unauthorized role creation or privilege escalation due to the lack of validation checks for existing roles before creating new ones. An attacker can exploit this by rapidly submitting role creation requests, potentially creating duplicate or unauthorized roles, bypassing access controls, and gaining elevated privileges.
You are affected if you are using a version that falls within the vulnerable range.
github.com/weaviate/weaviate is vulnerable to Race Condition in versions 1.28.3 - 1.28.8 and 1.29.0 - 1.29.0.
Upgrade the github.com/weaviate/weaviate library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant