CVE-2024-56323 Information

Description

OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19 docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObjects with a model that uses conditions and 2. calling Check API or ListObjects API with contextual tuples that include conditions and 3. OpenFGA is configured with caching enabled (OPENFGA_CHECK_QUERY_CACHE_ENABLED). Users are advised to upgrade to v1.8.3. There are no known workarounds for this vulnerability.

Reference

https://github.com/openfga/openfga/security/advisories/GHSA-32q6-rr98-cjqv

Share on: