CVE-2022-39352: OpenFGA Authorization Bypass
OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization bypass under certain conditions. You are affected by this vulnerability if you added a tuple with a wildcard () assigned to a tupleset relation (the right hand side of a ‘from’ statement). This issue has been patched in version v0.2.5. This update is not backward compatible with any authorization model that uses wildcard on a tupleset relation.
Other sources
OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. Versions prior to 0.2.5 are vulnerable to authorization bypass under certain conditions. You are affected by this vulnerability if you added a tuple with a wildcard () assigned to a tupleset relation (the right hand side of a ‘from’ statement). This issue has been patched in version v0.2.5. This update is not backward compatible with any authorization model that uses wildcard on a tupleset relation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-39352?
CVE-2022-39352 is a vulnerability in OpenFGA, a high-performance authorization/permission engine, that allows for authorization bypass under certain conditions.
How does the vulnerability in OpenFGA (CVE-2022-39352) occur?
The vulnerability in OpenFGA (CVE-2022-39352) occurs when a tuple with a wildcard (*) is added to a tupleset relation in versions prior to 0.2.5.
Am I affected by the OpenFGA vulnerability (CVE-2022-39352)?
You are affected by the OpenFGA vulnerability (CVE-2022-39352) if you added a tuple with a wildcard (*) assigned to a tupleset relation in a version prior to 0.2.5.
What is the severity of CVE-2022-39352?
The severity of CVE-2022-39352 is critical with a CVSS score of 9.8.
How can I fix the OpenFGA vulnerability (CVE-2022-39352)?
To fix the OpenFGA vulnerability (CVE-2022-39352), update OpenFGA to version 0.2.5 or above.