VYPR
High severity7.5NVD Advisory· Published Aug 12, 2024· Updated Jun 17, 2026

CVE-2024-42473

CVE-2024-42473

Description

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/openfga/openfgaGo
>= 1.5.7, < 1.5.91.5.9

Affected products

4
  • Openfga/Openfga3 versions
    cpe:2.3:a:openfga:openfga:1.5.7:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:openfga:openfga:1.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:openfga:openfga:1.5.8:*:*:*:*:*:*:*
    • (no CPE)range: >=1.5.7, <= 1.5.8
  • ghsa-coords
    Range: >= 1.5.7, < 1.5.9

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.