Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rxpw-85vw-fx87

Опубликовано: 26 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

OpenFGA denial of service

Overview

OpenFGA is vulnerable to a DoS attack. In some scenarios that depend on the model and tuples used, a call to ListObjects may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an "out of memory" error and terminate.

Fix

Upgrade to v1.4.3. This upgrade is backwards compatible.

Пакеты

Наименование

github.com/openfga/openfga

go
Затронутые версииВерсия исправления

< 1.4.3

1.4.3

EPSS

Процентиль: 21%
0.00069
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-401
CWE-770

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model and tuples used, a call to `ListObjects` may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an `out of memory` error and terminate. Version 1.4.3 contains a patch for this issue.

EPSS

Процентиль: 21%
0.00069
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-401
CWE-770