QID 995623
Date Published: 2023-10-25
QID 995623: GO (Go) Security Update for github.com/openfga/openfga (GHSA-hr4f-6jh8-f2vq)
OpenFGA is vulnerable to a DoS attack. When a number of ListObjects calls are executed, in some scenarios, those calls are not releasing resources even after a response has been sent, and the service as a whole becomes unresponsive.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hr4f-6jh8-f2vq for updates and patch information.
Vendor References
- GHSA-hr4f-6jh8-f2vq -
github.com/advisories/GHSA-hr4f-6jh8-f2vq
CVEs related to QID 995623
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hr4f-6jh8-f2vq | github.com/openfga/openfga |
|