PT-2024-24086 · Openfga · Openfga

Miparnisari

·

Published

2024-04-16

·

Updated

2026-01-05

·

CVE-2024-31452

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenFGA versions 1.5.0 through 1.5.2
Description The issue concerns an authorization bypass when calling Check or ListObjects APIs in OpenFGA. Users are likely affected if their model involves exclusion (e.g., a but not b) or intersection (e.g., a and b), particularly if there are cyclical relationships.
Recommendations Update to version 1.5.3 to resolve the issue. As a temporary workaround, consider restricting the use of exclusion and intersection models, especially those with cyclical relationships, until the update is applied.

Exploit

Fix

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-31452
GHSA-8CPH-M685-6V6R
GO-2024-2729

Affected Products

Openfga