← back
CVE-2022-39341mediumCWE-285

OpenFGA Authorization Bypass

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.9epss 0.9%
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
In short

OpenFGA, an authorization system, had a flaw where wildcards in permission rules could be bypassed, allowing unauthorized access. This matters because it undermines the security of applications relying on OpenFGA to protect sensitive operations.

Technical detail

OpenFGA versions before 0.2.4 contain an authorization bypass vulnerability affecting tupleset relations with wildcard (`*`) definitions in the authorization model. Attackers can exploit this to circumvent intended access controls without requiring special privileges or authentication bypass, leading to unauthorized access to protected resources.

Summary generated and translated by AI from the official description.
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users who have wildcard (`*`) defined on tupleset relations in their authorization model are vulnerable. Version 0.2.4 contains a patch for this issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
openfga · openfga