VDB
Sign up
MEDIUM

GHSA-32q6-rr98-cjqv

OpenFGA Authorization Bypass

Quick fix

GHSA-32q6-rr98-cjqv — github.com/openfga/openfga: upgrade to the fixed version with the command below.

go get github.com/openfga/openfga@v1.8.3

Details

### Overview OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.

### Am I Affected? You are affected by this authorization bypass vulnerability if you are using OpenFGA v1.3.8 to v1.8.2, specifically under the following conditions: 1. Calling Check API or ListObjects with a model that uses [conditions](https://openfga.dev/docs/modeling/conditions), and 2. OpenFGA is configured with caching enabled (`OPENFGA_CHECK_QUERY_CACHE_ENABLED`), and 3. Check API call or ListObjects API calls contain [contextual tuples](https://openfga.dev/docs/concepts#what-are-contextual-tuples) that include conditions.

### Fix Upgrade to v1.8.3. This upgrade is backwards compatible.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/openfga/openfga
Introduced in: 1.3.8Fixed in: 1.8.3
Fixgo get github.com/openfga/openfga@v1.8.3

References