GHSA-32q6-rr98-cjqv
OpenFGA Authorization Bypass
Quick fix
GHSA-32q6-rr98-cjqv — github.com/openfga/openfga: upgrade to the fixed version with the command below.
go get github.com/openfga/openfga@v1.8.3Details
### Overview OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.
### Am I Affected? You are affected by this authorization bypass vulnerability if you are using OpenFGA v1.3.8 to v1.8.2, specifically under the following conditions: 1. Calling Check API or ListObjects with a model that uses [conditions](https://openfga.dev/docs/modeling/conditions), and 2. OpenFGA is configured with caching enabled (`OPENFGA_CHECK_QUERY_CACHE_ENABLED`), and 3. Check API call or ListObjects API calls contain [contextual tuples](https://openfga.dev/docs/concepts#what-are-contextual-tuples) that include conditions.
### Fix Upgrade to v1.8.3. This upgrade is backwards compatible.
Are you affected?
Enter the version of the package you're using.
Affected packages
1.3.8Fixed in: 1.8.3go get github.com/openfga/openfga@v1.8.3