OpenFGA
cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*
- >= v1.8.0, <= v1.13.1
A vulnerability in OpenFGA versions 1.8.0 prior to 1.13.1 allows for improper policy enforcement during BatchCheck operations. This issue arises when multiple checks are sent for the same object, relation, and user combination, and the contexts of these checks differ in a specific way. Under these conditions, the authorization engine may not enforce policies correctly, potentially leading to unauthorized access or permissions.
Exploitation of this vulnerability can result in improper enforcement of authorization policies, allowing for potential unauthorized access or permissions.
Users can upgrade to OpenFGA version 1.14.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.