Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0007 | OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObjects with a model that uses [conditions](https://openfga.dev/docs/modeling/conditions), and 2. calling Check API or ListObjects API with [contextual tuples](https://openfga.dev/docs/concepts#what-are-contextual-tuples) that include conditions and 3. OpenFGA is configured with caching enabled (`OPENFGA_CHECK_QUERY_CACHE_ENABLED`). Users are advised to upgrade to v1.8.3. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-32q6-rr98-cjqv | OpenFGA Authorization Bypass |
Wed, 31 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openfga helm Charts
|
|
| CPEs | cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:*:*:* cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Openfga helm Charts
|
|
| Metrics |
cvssV3_1
|
Tue, 14 Jan 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Jan 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObjects with a model that uses [conditions](https://openfga.dev/docs/modeling/conditions), and 2. calling Check API or ListObjects API with [contextual tuples](https://openfga.dev/docs/concepts#what-are-contextual-tuples) that include conditions and 3. OpenFGA is configured with caching enabled (`OPENFGA_CHECK_QUERY_CACHE_ENABLED`). Users are advised to upgrade to v1.8.3. There are no known workarounds for this vulnerability. | |
| Title | OpenFGA Authorization Bypass | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-14T00:29:58.019Z
Reserved: 2024-12-18T23:44:51.604Z
Link: CVE-2024-56323
Updated: 2025-01-14T00:29:52.890Z
Status : Analyzed
Published: 2025-01-13T22:15:14.447
Modified: 2025-12-31T14:58:38.370
Link: CVE-2024-56323
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:56Z
EUVD
Github GHSA