PT-2025-18316 · Openfga · Openfga

·

CVE-2025-46331

·

Publicado

2025-04-30

·

Atualizado

2025-05-20

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenFGA versions 1.3.6 through 1.8.10
Description OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. The issue concerns an authorization bypass when certain Check and ListObject calls are executed. This problem has been corrected in version 1.8.11.
Recommendations For versions 1.3.6 through 1.8.10, update to version 1.8.11 to resolve the issue.

Exploit

Correção

Incorrect Authorization

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-46331
ECHO-3774-CD30-2AE0
GHSA-W222-M46C-MGH6
GO-2025-3657
OPENSUSE-SU-2025:15135-1

Produtos afetados

Openfga