Vulnerabilities
Vulnerable Software
Openfga:  >> Openfga  >> 0.2.4  Security Vulnerabilities
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.
CVSS Score
7.7
EPSS Score
0.004
Published
2022-12-20
OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization bypass under certain conditions. You are affected by this vulnerability if you added a tuple with a wildcard (*) assigned to a tupleset relation (the right hand side of a ‘from’ statement). This issue has been patched in version v0.2.5. This update is not backward compatible with any authorization model that uses wildcard on a tupleset relation.
CVSS Score
4.8
EPSS Score
0.003
Published
2022-11-08


Contact Us

Shodan ® - All rights reserved