VDB
Sign up
MEDIUM5.0

GHSA-jwvj-g8pc-cx45

OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision

Quick fix

GHSA-jwvj-g8pc-cx45 — github.com/openfga/openfga: upgrade to the fixed version with the command below.

go get github.com/openfga/openfga@v1.14.0

Details

### Description

In OpenFGA, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement.

### Am I affected?

You are affected if you meet the following preconditions: 1. You execute **BatchCheck** operations which rely on context. 2. Multiple checks are sent within a single BatchCheck operation for the same user/object/relation combination, each containing context. 3. The contexts between those checks differ in a specific way

### Fix Upgrade to OpenFGA v1.14.0

### Acknowledgement OpenFGA would like to thank @bugbunny-research for the discovery and detailed report.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/openfga/openfga
Introduced in: 1.8.0Fixed in: 1.14.0
Fixgo get github.com/openfga/openfga@v1.14.0

References