Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95x7-mh78-7w2r

Опубликовано: 25 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

OpenFGA subject to Information Disclosure via streamed-list-objects endpoint

Overview

During our internal security assessment, it was discovered that streamed-list-objects endpoint was not validating the authorization header resulting in the disclosure of objects in the store.

Am I Affected?

You are affected by this vulnerability if you are using openfga/openfga version v0.2.3 or prior and you are exposing the OpenFGA service to the internet.

How to fix that?

Upgrade to version v0.2.4.

Backward Compatibility

This update is backward compatible.

Пакеты

Наименование

github.com/openfga/openfga

go
Затронутые версииВерсия исправления

<= 0.2.3

0.2.4

EPSS

Процентиль: 48%
0.0025
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285
CWE-862
CWE-863

Связанные уязвимости

CVSS3: 5.3
nvd
больше 3 лет назад

OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA service to the internet are vulnerable. Version 0.2.4 contains a patch for this issue.

EPSS

Процентиль: 48%
0.0025
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285
CWE-862
CWE-863