PT-2025-3267 · Openfga+1 · Openfga+1
Miparnisari
·
Published
2025-01-13
·
Updated
2025-12-31
·
CVE-2024-56323
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenFGA versions 1.3.8 through 1.8.2
Description
The issue concerns an authorization bypass in OpenFGA under specific conditions, including calling Check API or ListObjects with a model that uses
conditions, and OpenFGA being configured with caching enabled (OPENFGA CHECK QUERY CACHE ENABLED). This occurs when Check API or ListObjects API calls contain contextual tuples that include conditions.Recommendations
For OpenFGA versions 1.3.8 through 1.8.2, upgrade to version 1.8.3, as this upgrade is backwards compatible.
As a temporary workaround, consider disabling caching by setting
OPENFGA CHECK QUERY CACHE ENABLED to false until the upgrade to version 1.8.3 is possible.
Avoid using conditions in models for Check API or ListObjects calls, and avoid using contextual tuples that include conditions in these API calls until the issue is resolved.Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openfga
Suse