Openfga

Openfga

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 17.10.2023 23:15:12
  • Zuletzt bearbeitet 21.11.2024 08:27:24

OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerable to a denial of service attack. When a number of `ListObjects` calls are executed, in some scenario...

  • EPSS 0.35%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 21.11.2024 08:24:32

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerable to a denial of service attack when certain Check calls are executed against authorization models that contain circular relations...

  • EPSS 0.07%
  • Veröffentlicht 25.08.2023 20:15:08
  • Zuletzt bearbeitet 21.11.2024 08:19:45

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects custome...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 26.06.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:09:00

OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vulnerable to a DoS attack when Check and ListObjects calls are executed against authorization models that contain circular relation...

  • EPSS 0.42%
  • Veröffentlicht 20.12.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 06:48:46

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. T...

  • EPSS 0.26%
  • Veröffentlicht 08.11.2022 08:15:09
  • Zuletzt bearbeitet 21.11.2024 07:18:05

OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization bypass under certain conditions. You are affected by this vulnerability if you added a tuple with a wil...

  • EPSS 0.25%
  • Veröffentlicht 25.10.2022 17:15:56
  • Zuletzt bearbeitet 21.11.2024 07:18:04

OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior...

  • EPSS 0.33%
  • Veröffentlicht 25.10.2022 17:15:56
  • Zuletzt bearbeitet 21.11.2024 07:18:04

OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users whose model has a relation defined as a tupleset (the right hand side of a ‘from’ statement) that in...

  • EPSS 0.33%
  • Veröffentlicht 25.10.2022 17:15:56
  • Zuletzt bearbeitet 21.11.2024 07:18:04

OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users who have wildcard (`*`) defined on tupleset relations in their authorization model are vulnerable. V...