PT-2023-29700 · Openfga · Openfga

Klausvii

·

Published

2023-10-17

·

Updated

2024-08-21

·

CVE-2023-45810

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenFGA versions prior to 1.3.4
Description OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerable to a denial of service attack. When a number of ListObjects calls are executed, in some scenarios, those calls are not releasing resources even after a response has been sent, and given a sufficient call volume the service as a whole becomes unresponsive.
Recommendations Upgrade to version 1.3.4, as this upgrade is backwards compatible and addresses the issue. There are no known workarounds for this vulnerability.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2023-45810
GHSA-HR4F-6JH8-F2VQ
GO-2023-2121

Affected Products

Openfga