PT-2023-29700 · Openfga · Openfga

Klausvii

·

Publicado

2023-10-17

·

Atualizado

2024-08-21

·

CVE-2023-45810

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenFGA versions prior to 1.3.4
Description OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerable to a denial of service attack. When a number of ListObjects calls are executed, in some scenarios, those calls are not releasing resources even after a response has been sent, and given a sufficient call volume the service as a whole becomes unresponsive.
Recommendations Upgrade to version 1.3.4, as this upgrade is backwards compatible and addresses the issue. There are no known workarounds for this vulnerability.

Exploit

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-45810
GHSA-HR4F-6JH8-F2VQ
GO-2023-2121

Produtos afetados

Openfga