CVE-2022-23542

HIGH

OpenFGA 0.3.0 - Authorization Bypass

Title source: llm
STIX 2.1

Description

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.

References (3)

Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/openfga/openfga/pull/422
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/openfga/openfga/releases/tag/v0.3.1

Scores

CVSS v3 7.7
EPSS 0.0091
EPSS Percentile 55.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-285
Status published
Products (2)
openfga/openfga < 0.3.1
openfga/openfga 0.3.0 - 0.3.1Go
Published Dec 20, 2022
Tracked Since Feb 18, 2026