Логотип exploitDog
bind:CVE-2022-39340
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39340

Количество 2

Количество 2

nvd логотип

CVE-2022-39340

больше 3 лет назад

OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA service to the internet are vulnerable. Version 0.2.4 contains a patch for this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-95x7-mh78-7w2r

больше 3 лет назад

OpenFGA subject to Information Disclosure via streamed-list-objects endpoint

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-39340

OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA service to the internet are vulnerable. Version 0.2.4 contains a patch for this issue.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-95x7-mh78-7w2r

OpenFGA subject to Information Disclosure via streamed-list-objects endpoint

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу