Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-42473

Опубликовано: 12 авг. 2024
Источник: nvd
CVSS3: 7.5
CVSS3: 9.8
EPSS Низкий

Описание

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openfga:openfga:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:openfga:openfga:1.5.8:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.00067
Низкий

7.5 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

OpenFGA Authorization Bypass

EPSS

Процентиль: 21%
0.00067
Низкий

7.5 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-863
CWE-863