CVE-2024-42473: OpenFGA Authorization Bypass
Overview
OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset.
Fix
- If you are using OpenFGA within Docker or as a Go library, as a binary, or through Docker, upgrade to v1.5.9 as soon as possible - If using Helm chart, upgrade to 0.2.12 as soon as possible.
This fix is backward compatible.
Other sources
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset. Users should downgrade to v1.5.6 as soon as possible. This downgrade is backward compatible. As of time of publication, a patch is not available but OpenFGA's maintainers are planning a patch for inclusion in a future release.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42473?
CVE-2024-42473 has a significant severity due to its potential for authorization bypass in OpenFGA versions 1.5.7 and 1.5.8.
How do I fix CVE-2024-42473?
To fix CVE-2024-42473, you should upgrade OpenFGA to version 1.5.9 or later.
What versions of OpenFGA are affected by CVE-2024-42473?
CVE-2024-42473 affects OpenFGA versions 1.5.7 and 1.5.8.
What method is vulnerable in CVE-2024-42473?
CVE-2024-42473 involves an authorization bypass when calling the Check API with specific model expressions.
Can I use OpenFGA in a Docker environment with CVE-2024-42473?
If using OpenFGA in Docker, ensure you upgrade to version 1.5.9 to mitigate CVE-2024-42473.