CVE-2022-39340: OpenFGA Information Disclosure
OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the streamed-list-objects endpoint was not validating the authorization header, resulting in disclosure of objects in the store. Users openfga/openfga versions 0.2.3 and prior who are exposing the OpenFGA service to the internet are vulnerable. Version 0.2.4 contains a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-39340?
CVE-2022-39340 is a vulnerability in OpenFGA, an authorization/permission engine, where the `streamed-list-objects` endpoint does not validate the authorization header, allowing disclosure of objects in the store.
How severe is CVE-2022-39340?
CVE-2022-39340 has a severity score of 5.3, which is considered medium.
How can I fix CVE-2022-39340?
To fix CVE-2022-39340, users should upgrade their OpenFGA version to 0.2.4 or higher.
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2022-39340.
What are the affected versions of OpenFGA?
OpenFGA versions prior to 0.2.4 are affected by CVE-2022-39340.