PT-2022-24911 · Openfga · Openfga

Samyghannad

·

Published

2022-10-25

·

Updated

2024-08-21

·

CVE-2022-39341

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenFGA versions prior to 0.2.4
Description OpenFGA is an authorization/permission engine. The issue allows for authorization bypass under certain conditions, specifically when users have a wildcard (*) defined on tupleset relations in their authorization model.
Recommendations Upgrade to version 0.2.4 to resolve the issue. As a temporary workaround, consider restricting the use of wildcard (*) on tupleset relations in the authorization model until the update is applied.

Exploit

Fix

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-39341
GHSA-VJ4M-83M8-XPW5
GO-2022-1080

Affected Products

Openfga