Описание
OpenFGA subject to Information Disclosure via streamed-list-objects endpoint
Overview
During our internal security assessment, it was discovered that streamed-list-objects endpoint was not validating the authorization header resulting in the disclosure of objects in the store.
Am I Affected?
You are affected by this vulnerability if you are using openfga/openfga version v0.2.3 or prior and you are exposing the OpenFGA service to the internet.
How to fix that?
Upgrade to version v0.2.4.
Backward Compatibility
This update is backward compatible.
Пакеты
github.com/openfga/openfga
<= 0.2.3
0.2.4
Связанные уязвимости
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA service to the internet are vulnerable. Version 0.2.4 contains a patch for this issue.