Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2475 | OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release. |
Github GHSA |
GHSA-3f6g-m4hr-59h8 | OpenFGA Authorization Bypass |
Tue, 01 Oct 2024 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:openfga:openfga:1.5.7:*:*:*:*:*:*:* cpe:2.3:a:openfga:openfga:1.5.8:*:*:*:*:*:*:* |
Sat, 10 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openfga
Openfga openfga |
|
| CPEs | cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openfga
Openfga openfga |
|
| Metrics |
ssvc
|
Fri, 09 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release. | |
| Title | OpenFGA Authorization Bypass | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-10T14:21:04.103Z
Reserved: 2024-08-02T14:13:04.615Z
Link: CVE-2024-42473
Updated: 2024-08-10T14:20:30.724Z
Status : Analyzed
Published: 2024-08-12T13:38:35.680
Modified: 2024-10-01T12:21:50.327
Link: CVE-2024-42473
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA