Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8cph-m685-6v6r

Опубликовано: 16 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

OpenFGA Authorization Bypass

Overview

Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs.

Am I Affected?

You are very likely affected if your model involves exclusion (e.g. a but not b) or intersection (e.g. a and b) and you have any cyclical relationships. If you are using these, please update as soon as possible.

Fix

Update to v1.5.3

Backward Compatibility

This update is backward compatible.

Пакеты

Наименование

github.com/openfga/openfga

go
Затронутые версииВерсия исправления

>= 1.5.0, < 1.5.3

1.5.3

EPSS

Процентиль: 31%
0.00117
Низкий

8.1 High

CVSS3

Дефекты

CWE-285
CWE-863

Связанные уязвимости

CVSS3: 8.1
nvd
почти 2 года назад

OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs. You are very likely affected if your model involves exclusion (e.g. `a but not b`) or intersection (e.g. `a and b`). This vulnerability is fixed in v1.5.3.

EPSS

Процентиль: 31%
0.00117
Низкий

8.1 High

CVSS3

Дефекты

CWE-285
CWE-863