Описание
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.
Ссылки
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.3.1 (исключая)
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.0042
Низкий
7.7 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-285
Связанные уязвимости
EPSS
Процентиль: 61%
0.0042
Низкий
7.7 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-285