CVE-2023-40579: OpenFGA Authorization Bypass
Overview Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. This means that the API sometimes returns more objects than it should.
Am I Affected? The vulnerability affects customers using ListObjects with specific models. The affected models contain expressions of type rel1 from type1.
Fix Update to v1.3.1.
Backward Compatibility This update is backward compatible.
Other sources
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using ListObjects with specific models. The affected models contain expressions of type rel1 from type1. This issue has been patched in version 1.3.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40579?
CVE-2023-40579 is a vulnerability in OpenFGA that allows for authorization bypass when calling the ListObjects API, resulting in more objects being returned than intended.
Who is affected by CVE-2023-40579?
Customers using OpenFGA v1.3.0 or earlier, specifically those using the ListObjects API with specific parameters, are affected by CVE-2023-40579.
How severe is CVE-2023-40579?
CVE-2023-40579 has a severity rating of medium, with a CVSS score of 6.5 (out of 10).
How can I fix CVE-2023-40579?
To fix CVE-2023-40579, affected customers should update to OpenFGA v1.3.1 or later.
Where can I find more information about CVE-2023-40579?
More information about CVE-2023-40579 can be found on the OpenFGA GitHub security advisory, the OpenFGA releases page, and the NIST NVD website.