Описание
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.
A flaw was found in OpenFGA, an authorization/permission engine. When iterator caching is enabled, distinct authorization check requests can generate identical cache keys. This can cause OpenFGA to reuse an outdated or incorrect cached result for subsequent requests. Such a flaw may lead to unauthorized information disclosure, data integrity issues, or denial of service with low impact.
Меры по смягчению последствий
To mitigate this issue, disable iterator caching in OpenFGA configurations. This prevents the generation of identical cache keys for distinct authorization requests, thereby eliminating the risk of reusing outdated or incorrect cached results. Consult OpenFGA documentation for specific configuration parameters related to iterator caching. Disabling this feature may impact performance depending on the workload, and a service restart may be required for the changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Fix deferred | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 6 | rhceph/rhceph-6-dashboard-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 7 | rhceph/grafana-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 8 | rhceph/grafana-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 9 | rhceph/grafana-rhel10 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | grafana | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS3
Связанные уязвимости
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
EPSS
5 Medium
CVSS3