QID 995457

Date Published: 2023-10-03

QID 995457: GO (Go) Security Update for github.com/openfga/openfga (GHSA-2hm9-h873-pgqh)

OpenFGA is vulnerable to a DoS attack when certain Check calls are executed against authorization models that contain circular relationship definitions. When the call is made, it's possible for the server to exhaust resources and die.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-2hm9-h873-pgqh for updates and patch information.
    Vendor References

    CVEs related to QID 995457

    Software Advisories
    Advisory ID Software Component Link
    GHSA-2hm9-h873-pgqh github.com/openfga/openfga URL Logo github.com/advisories/GHSA-2hm9-h873-pgqh