Openfga

Openfga

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 13.01.2025 22:15:14
  • Zuletzt bearbeitet 31.12.2025 14:58:38

OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) are vulnerable to authorization bypass under the following conditions: 1. calling Check API or ListObj...

  • EPSS 0.07%
  • Veröffentlicht 12.08.2024 13:38:35
  • Zuletzt bearbeitet 01.10.2024 12:21:50

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as ...

  • EPSS 0.09%
  • Veröffentlicht 16.04.2024 22:15:35
  • Zuletzt bearbeitet 05.01.2026 16:20:42

OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs. You are very likely affected if your model involves e...

  • EPSS 0.09%
  • Veröffentlicht 26.01.2024 17:15:13
  • Zuletzt bearbeitet 21.11.2024 08:58:29

OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model and tuples used, a call to `ListObjects` may not release memory properly. So when a suffi...

  • EPSS 0.07%
  • Veröffentlicht 17.10.2023 23:15:12
  • Zuletzt bearbeitet 21.11.2024 08:27:24

OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerable to a denial of service attack. When a number of `ListObjects` calls are executed, in some scenario...

  • EPSS 0.35%
  • Veröffentlicht 27.09.2023 15:19:34
  • Zuletzt bearbeitet 21.11.2024 08:24:32

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerable to a denial of service attack when certain Check calls are executed against authorization models that contain circular relations...

  • EPSS 0.07%
  • Veröffentlicht 25.08.2023 20:15:08
  • Zuletzt bearbeitet 21.11.2024 08:19:45

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects custome...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 26.06.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:09:00

OPenFGA is an open source authorization/permission engine built for developers. OpenFGA versions v1.1.0 and prior are vulnerable to a DoS attack when Check and ListObjects calls are executed against authorization models that contain circular relation...

  • EPSS 0.42%
  • Veröffentlicht 20.12.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 06:48:46

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. T...

  • EPSS 0.26%
  • Veröffentlicht 08.11.2022 08:15:09
  • Zuletzt bearbeitet 21.11.2024 07:18:05

OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization bypass under certain conditions. You are affected by this vulnerability if you added a tuple with a wil...