CVE-2023-40579: OpenFGA Authorization Bypass

Published Aug 25, 2023
·
Updated

Overview Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. This means that the API sometimes returns more objects than it should.

Am I Affected? The vulnerability affects customers using ListObjects with specific models. The affected models contain expressions of type rel1 from type1.

Fix Update to v1.3.1.

Backward Compatibility This update is backward compatible.

Other sources

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using ListObjects with specific models. The affected models contain expressions of type rel1 from type1. This issue has been patched in version 1.3.1.

Affected Software

2 affected componentsFixes available
go/github.com/openfga/openfga<1.3.1
1.3.1
OPenFGA OPenFGA<1.3.1

Event History

Aug 25, 2023
Advisory Published
via GitHub·07:45 PM
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2023-40579?

CVE-2023-40579 is a vulnerability in OpenFGA that allows for authorization bypass when calling the ListObjects API, resulting in more objects being returned than intended.

2

Who is affected by CVE-2023-40579?

Customers using OpenFGA v1.3.0 or earlier, specifically those using the ListObjects API with specific parameters, are affected by CVE-2023-40579.

3

How severe is CVE-2023-40579?

CVE-2023-40579 has a severity rating of medium, with a CVSS score of 6.5 (out of 10).

4

How can I fix CVE-2023-40579?

To fix CVE-2023-40579, affected customers should update to OpenFGA v1.3.1 or later.

5

Where can I find more information about CVE-2023-40579?

More information about CVE-2023-40579 can be found on the OpenFGA GitHub security advisory, the OpenFGA releases page, and the NIST NVD website.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203