OpenFGA
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*
- >= 1.4.0, <= 1.11.0
A vulnerability exists in OpenFGA versions 1.4.0 prior to 1.11.0, including specific Helm chart and Docker package versions, due to improper policy enforcement. This issue arises when certain Check and ListObject calls are made, potentially leading to authorization problems by allowing unintended access or permissions.
Exploitation of this vulnerability could result in improper authorization checks, allowing users to bypass certain access controls or permissions. This could lead to unauthorized actions or access within the application.
Users can upgrade to OpenFGA version 1.11.1, which addresses this vulnerability. This upgrade is backwards compatible.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.