Skip to content

OpenFGA Information Disclosure

Moderate
SamyGhannad published GHSA-95x7-mh78-7w2r Oct 24, 2022

Package

gomod github.com/openfga/openfga (Go)

Affected versions

<= 0.2.3

Patched versions

0.2.4

Description

Overview

During our internal security assessment, it was discovered that streamed-list-objects endpoint was not validating the authorization header resulting in the disclosure of objects in the store.

Am I Affected?

You are affected by this vulnerability if you are using openfga/openfga version v0.2.3 or prior and you are exposing the OpenFGA service to the internet.

How to fix that?

Upgrade to version v0.2.4.

Backward Compatibility

This update is backward compatible.

Severity

Moderate

CVE ID

CVE-2022-39340

Weaknesses

No CWEs