OpenFGA Authorization Bypass
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.7epss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
In short
OpenFGA versions before 0.3.1 have a flaw that allows attackers to bypass authorization checks under certain conditions, potentially gaining unauthorized access to protected resources or actions.
Technical detail
OpenFGA 0.3.0 contains an authorization bypass vulnerability (CWE-285) that permits attackers to circumvent permission enforcement mechanisms. The vulnerability requires specific preconditions to be met; exploitation results in unauthorized access to restricted functionality. The flaw was remediated in version 0.3.1 with backward compatibility maintained.
Summary generated and translated by AI from the official description.
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Affected products
openfga · openfga