PT-2023-29700 · Openfga · Openfga
Klausvii
·
Published
2023-10-17
·
Updated
2024-08-21
·
CVE-2023-45810
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenFGA versions prior to 1.3.4
Description
OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerable to a denial of service attack. When a number of
ListObjects calls are executed, in some scenarios, those calls are not releasing resources even after a response has been sent, and given a sufficient call volume the service as a whole becomes unresponsive.Recommendations
Upgrade to version 1.3.4, as this upgrade is backwards compatible and addresses the issue. There are no known workarounds for this vulnerability.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openfga