PT-2023-27517 · Openfga · Openfga

Aaguiarz

·

Publicado

2023-08-25

·

Atualizado

2024-08-21

·

CVE-2023-40579

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenFGA versions 1.3.0 and earlier
Description The issue affects OpenFGA, an authorization/permission engine, where some end users of versions 1.3.0 or earlier are vulnerable to authorization bypass when calling the "ListObjects" API endpoint. This means the API sometimes returns more objects than it should. The vulnerability affects customers using ListObjects with specific models, particularly those containing expressions of type rel1 from type1.
Recommendations Update to version 1.3.1, as this update is backward compatible and patches the issue. As a temporary workaround, consider restricting the use of the ListObjects API endpoint with models containing expressions of type rel1 from type1 until the update is applied.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40579
GHSA-JCF2-MXR2-GMQP
GO-2023-2028

Produtos afetados

Openfga