OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.
References
Link | Resource |
---|---|
https://github.com/openfga/openfga/pull/422 | Patch Third Party Advisory |
https://github.com/openfga/openfga/releases/tag/v0.3.1 | Release Notes Third Party Advisory |
https://github.com/openfga/openfga/security/advisories/GHSA-m3q4-7qmj-657m | Third Party Advisory |
https://github.com/openfga/openfga/pull/422 | Patch Third Party Advisory |
https://github.com/openfga/openfga/releases/tag/v0.3.1 | Release Notes Third Party Advisory |
https://github.com/openfga/openfga/security/advisories/GHSA-m3q4-7qmj-657m | Third Party Advisory |
Configurations
History
21 Nov 2024, 06:48
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.7 |
References | () https://github.com/openfga/openfga/pull/422 - Patch, Third Party Advisory | |
References | () https://github.com/openfga/openfga/releases/tag/v0.3.1 - Release Notes, Third Party Advisory | |
References | () https://github.com/openfga/openfga/security/advisories/GHSA-m3q4-7qmj-657m - Third Party Advisory |
07 Nov 2023, 03:44
Type | Values Removed | Values Added |
---|---|---|
Summary | OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible. |
Information
Published : 2022-12-20 21:15
Updated : 2024-11-21 06:48
NVD link : CVE-2022-23542
Mitre link : CVE-2022-23542
CVE.ORG link : CVE-2022-23542
JSON object : View
Products Affected
openfga
- openfga
CWE
CWE-285
Improper Authorization