← back
CVE-2022-39340mediumCWE-285

OpenFGA Information Disclosure

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 0.7%
exploitation probability
0.7%top 52% of all CVEs
observed exploitation
nono source reports it
In short

OpenFGA's streamed-list-objects endpoint failed to validate authorization headers, allowing attackers to view objects stored in the system without proper permission. This affects versions 0.2.3 and earlier when exposed to the internet.

Technical detail

The streamed-list-objects endpoint in OpenFGA versions ≤0.2.3 does not enforce authorization header validation, enabling unauthorized information disclosure of stored objects. The vulnerability requires network access to the exposed endpoint; patched in version 0.2.4.

Summary generated and translated by AI from the official description.
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users `openfga/openfga` versions 0.2.3 and prior who are exposing the OpenFGA service to the internet are vulnerable. Version 0.2.4 contains a patch for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
openfga · openfga