← Back

CVE-2024-31452

nvd nist
Published: Apr 16, 2024Modified: Jan 5, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs. You are very likely affected if your model involves exclusion (e.g. `a but not b`) or intersection (e.g. `a and b`). This vulnerability is fixed in v1.5.3.

Affected (1)

Products: Openfga: Openfga
1 product
Openfga
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.5.0 to 1.5.3

References (4)

Source: security-advisories@github.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.