GHSA-jwvj-g8pc-cx45
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
Quick fix
GHSA-jwvj-g8pc-cx45 — github.com/openfga/openfga: upgrade to the fixed version with the command below.
go get github.com/openfga/openfga@v1.14.0Details
### Description
In OpenFGA, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement.
### Am I affected?
You are affected if you meet the following preconditions: 1. You execute **BatchCheck** operations which rely on context. 2. Multiple checks are sent within a single BatchCheck operation for the same user/object/relation combination, each containing context. 3. The contexts between those checks differ in a specific way
### Fix Upgrade to OpenFGA v1.14.0
### Acknowledgement OpenFGA would like to thank @bugbunny-research for the discovery and detailed report.
Are you affected?
Enter the version of the package you're using.
Affected packages
1.8.0Fixed in: 1.14.0go get github.com/openfga/openfga@v1.14.0