CVE-2024-42473: OpenFGA Authorization Bypass

Published Aug 9, 2024
·
Updated

Overview

OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset.

Fix

- If you are using OpenFGA within Docker or as a Go library, as a binary, or through Docker, upgrade to v1.5.9 as soon as possible - If using Helm chart, upgrade to 0.2.12 as soon as possible.

This fix is backward compatible.

Other sources

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release.

NVD

Affected Software

3 affected componentsFixes available
go/github.com/openfga/openfga>=1.5.7<1.5.9
1.5.9
OPenFGA OPenFGA=1.5.7
OPenFGA OPenFGA=1.5.8

Event History

Aug 9, 2024
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:23 PM
Aug 12, 2024
Data Sourced
via NVD·01:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-42473?

CVE-2024-42473 has a significant severity due to its potential for authorization bypass in OpenFGA versions 1.5.7 and 1.5.8.

2

How do I fix CVE-2024-42473?

To fix CVE-2024-42473, you should upgrade OpenFGA to version 1.5.9 or later.

3

What versions of OpenFGA are affected by CVE-2024-42473?

CVE-2024-42473 affects OpenFGA versions 1.5.7 and 1.5.8.

4

What method is vulnerable in CVE-2024-42473?

CVE-2024-42473 involves an authorization bypass when calling the Check API with specific model expressions.

5

Can I use OpenFGA in a Docker environment with CVE-2024-42473?

If using OpenFGA in Docker, ensure you upgrade to version 1.5.9 to mitigate CVE-2024-42473.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203