OpenFGA subject to Information Disclosure via streamed-list-objects endpoint
Description
Published by the National Vulnerability Database
Oct 25, 2022
Published to the GitHub Advisory Database
Oct 25, 2022
Reviewed
Oct 25, 2022
Last updated
Jun 27, 2023
Overview
During our internal security assessment, it was discovered that
streamed-list-objects
endpoint was not validating the authorization header resulting in the disclosure of objects in the store.Am I Affected?
You are affected by this vulnerability if you are using
openfga/openfga
versionv0.2.3
or prior and you are exposing the OpenFGA service to the internet.How to fix that?
Upgrade to version
v0.2.4
.Backward Compatibility
This update is backward compatible.
References