QID 996896
Date Published: 2024-01-29
QID 996896: GO (Go) Security Update for github.com/openfga/openfga (GHSA-rxpw-85vw-fx87)
OpenFGA is vulnerable to a DoS attack. In some scenarios that depend on the model and tuples used, a call to ListObjects may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an "out of memory" error and terminate.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rxpw-85vw-fx87 for updates and patch information.
Vendor References
- GHSA-rxpw-85vw-fx87 -
github.com/advisories/GHSA-rxpw-85vw-fx87
CVEs related to QID 996896
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rxpw-85vw-fx87 | github.com/openfga/openfga |
|