VDB
KO
LOW

GHSA-cf98-j28v-49v6

OpenFGA Improper Policy Enforcement

Details

## Description

In OpenFGA, when MySQL is being used as the datastore, two distinct check requests can return the same response.

## Preconditions

This applies if the following preconditions are met:

1. You run OpenFGA with MySQL as the datastore 2. Your authorization decisions rely on case-sensitive user strings.

## Fix Upgrade to OpenFGA 1.18.0 or greater.

## Acknowledgements OpenFGA would like to thank @sahajamoth for the detailed report.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/openfga/openfga
Introduced in: 0 Fixed in: 1.18.0
Fix go get github.com/openfga/openfga@v1.18.0

References