Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c64-vmv2-hgfc

Опубликовано: 20 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.8

Описание

OpenFGA Improper Policy Enforcement

Overview

OpenFGA v1.4.0 to v1.11.0 (openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed.

Am I Affected?

You are affected by this vulnerability if you meet the following preconditions:

  • You are using OpenFGA v1.4.0 to v1.11.0
  • The model has a a relation directly assignable by a type bound pubic access with condition
  • The same relation is not assignable by a type bound public access without condition
  • You have a type assigned for the same relation that is a type bound public access without condition

Fix

Upgrade to v1.11.1. This upgrade is backwards compatible.

Workaround

None

Пакеты

Наименование

github.com/openfga/openfga

go
Затронутые версииВерсия исправления

>= 1.4.0, < 1.11.1

1.11.1

EPSS

Процентиль: 19%
0.00062
Низкий

5.8 Medium

CVSS4

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Check and ListObject calls are executed. This issue has been patched in version 1.11.1.

suse-cvrf
около 2 месяцев назад

Security update for grafana

EPSS

Процентиль: 19%
0.00062
Низкий

5.8 Medium

CVSS4

Дефекты

CWE-285