CVE-2022-39341: OpenFGA Authorization Bypass
OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users who have wildcard () defined on tupleset relations in their authorization model are vulnerable. Version 0.2.4 contains a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-39341?
CVE-2022-39341 is a vulnerability in the OpenFGA authorization/permission engine that allows for authorization bypass under certain conditions.
How severe is CVE-2022-39341?
CVE-2022-39341 has a severity rating of critical, with a CVSS score of 9.8.
Which versions of OpenFGA are affected by CVE-2022-39341?
Versions of OpenFGA prior to version 0.2.4 are affected by CVE-2022-39341.
How can I fix CVE-2022-39341?
To fix CVE-2022-39341, it is recommended to update to version 0.2.4 of OpenFGA, which contains a patch for this vulnerability.
Where can I find more information about CVE-2022-39341?
More information about CVE-2022-39341 can be found in the references section of the vulnerability.