CVE-2023-40579

MEDIUM

OpenFGA < 1.3.1 - Authorization Bypass via ListObjects API

Title source: llm
STIX 2.1

Description

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier are vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using `ListObjects` with specific models. The affected models contain expressions of type `rel1 from type1`. This issue has been patched in version 1.3.1.

References (2)

Core 2
Core References

Scores

CVSS v3 6.5
EPSS 0.0045
EPSS Percentile 36.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
openfga/openfga < 1.3.1
openfga/openfga 0 - 1.3.1Go
Published Aug 25, 2023
Tracked Since Feb 18, 2026