PT-2025-3267 · Openfga+1 · Openfga+1

Miparnisari

·

Published

2025-01-13

·

Updated

2025-12-31

·

CVE-2024-56323

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenFGA versions 1.3.8 through 1.8.2
Description The issue concerns an authorization bypass in OpenFGA under specific conditions, including calling Check API or ListObjects with a model that uses conditions, and OpenFGA being configured with caching enabled (OPENFGA CHECK QUERY CACHE ENABLED). This occurs when Check API or ListObjects API calls contain contextual tuples that include conditions.
Recommendations For OpenFGA versions 1.3.8 through 1.8.2, upgrade to version 1.8.3, as this upgrade is backwards compatible. As a temporary workaround, consider disabling caching by setting OPENFGA CHECK QUERY CACHE ENABLED to false until the upgrade to version 1.8.3 is possible. Avoid using conditions in models for Check API or ListObjects calls, and avoid using contextual tuples that include conditions in these API calls until the issue is resolved.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-56323
GHSA-32Q6-RR98-CJQV
GO-2025-3384
OPENSUSE-SU-2025:14653-1
OPENSUSE-SU-2025_0297-1
SUSE-SU-2025:0297-1

Affected Products

Openfga
Suse