CVE-2024-31452: OpenFGA Authorization Bypass

Published Apr 16, 2024
·
Updated

Overview Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs.

Am I Affected? You are very likely affected if your model involves exclusion (e.g. a but not b) or intersection (e.g. a and b) and you have any cyclical relationships. If you are using these, please update as soon as possible.

Fix Update to v1.5.3

Backward Compatibility This update is backward compatible.

Other sources

OpenFGA is a high-performance and flexible authorization/permission engine. Some end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs. You are very likely affected if your model involves exclusion (e.g. a but not b) or intersection (e.g. a and b). This vulnerability is fixed in v1.5.3.

MITRE

Affected Software

2 affected componentsFixes available
go/github.com/openfga/openfga>=1.5.0<1.5.3
1.5.3
OPenFGA OPenFGA>=1.5.0<1.5.3

Event History

Apr 16, 2024
CVE Published
via MITRE·09:40 PM
Data Sourced
via MITRE·09:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyAffected Software
Advisory Published
via GitHub·10:57 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-31452?

CVE-2024-31452 is considered a significant security vulnerability due to its potential for authorization bypass.

2

Who is affected by CVE-2024-31452?

Users of OpenFGA versions 1.5.0 to 1.5.3, particularly those using exclusions or intersections in their access models, are affected.

3

How do I fix CVE-2024-31452?

To fix CVE-2024-31452, upgrade OpenFGA to version 1.5.3 or later.

4

What potential impacts does CVE-2024-31452 have?

CVE-2024-31452 can lead to unauthorized access to resources due to improper authorization checks in API calls.

5

What APIs are affected by CVE-2024-31452?

CVE-2024-31452 affects the Check and ListObjects APIs in OpenFGA.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203