VDB
Sign up
MEDIUM

GHSA-c72g-53hw-82q7

OpenFGA Authorization Bypass

Quick fix

GHSA-c72g-53hw-82q7 — github.com/openfga/openfga: upgrade to the fixed version with the command below.

go get github.com/openfga/openfga@v1.8.13

Details

### Overview OpenFGA v1.8.0 to v1.8.12 ( openfga-0.2.16 <= Helm chart <= openfga-0.2.31, v1.8.0 <= docker <= v.1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed.

### Am I Affected? If you are using OpenFGA v1.8.0 to v1.8.12, specifically under the following conditions, you are affected by this authorization bypass vulnerability: - Calling Check API or ListObjects with an [authorization model](https://openfga.dev/docs/concepts#what-is-an-authorization-model) that has a relationship directly assignable by both [type bound public access](https://openfga.dev/docs/concepts#what-is-type-bound-public-access) and [userset](https://openfga.dev/docs/modeling/building-blocks/usersets), and - There are check or list object queries with [contextual tuples](https://openfga.dev/docs/interacting/contextual-tuples) for the relationship that can be directly assignable by both [type bound public access](https://openfga.dev/docs/concepts#what-is-type-bound-public-access) and [userset](https://openfga.dev/docs/modeling/building-blocks/usersets), and - Those contextual tuples’s user field is an userset, and - Type bound public access tuples are not assigned to the relationship

### Fix Upgrade to v1.8.13. This upgrade is backwards compatible.

### Acknowledgments OpenFGA would like to thank @udyvish for discovering this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/openfga/openfga
Introduced in: 1.8.0Fixed in: 1.8.13
Fixgo get github.com/openfga/openfga@v1.8.13

References