OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model and tuples used, a call to `ListObjects` may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an `out of memory` error and terminate. Version 1.4.3 contains a patch for this issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0426 OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model and tuples used, a call to `ListObjects` may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an `out of memory` error and terminate. Version 1.4.3 contains a patch for this issue.
Github GHSA Github GHSA GHSA-rxpw-85vw-fx87 OpenFGA denial of service
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-29T18:13:51.862Z

Reserved: 2024-01-22T22:23:54.337Z

Link: CVE-2024-23820

cve-icon Vulnrichment

Updated: 2024-08-01T23:13:08.520Z

cve-icon NVD

Status : Modified

Published: 2024-01-26T17:15:13.287

Modified: 2024-11-21T08:58:29.340

Link: CVE-2024-23820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses