Описание
OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model and tuples used, a call to ListObjects may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an out of memory error and terminate. Version 1.4.3 contains a patch for this issue.
Ссылки
- Patch
- Release Notes
- Third Party Advisory
- Patch
- Release Notes
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.3 (исключая)
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00069
Низкий
5.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-770
CWE-401
Связанные уязвимости
EPSS
Процентиль: 21%
0.00069
Низкий
5.3 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-770
CWE-401