High severityNVD Advisory· Published Aug 9, 2024· Updated Aug 10, 2024
OpenFGA Authorization Bypass
CVE-2024-42473
Description
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/openfga/openfgaGo | >= 1.5.7, < 1.5.9 | 1.5.9 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-3f6g-m4hr-59h8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-42473ghsaADVISORY
- github.com/openfga/openfga/security/advisories/GHSA-3f6g-m4hr-59h8ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.