CVE-2022-23542

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-23542
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23542.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23542
Aliases
Published
2022-12-20T20:15:16Z
Modified
2025-10-22T18:26:41.085483Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L CVSS Calculator
Summary
OpenFGA Authorization Bypass
Details

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.

Database specific
{
    "cwe_ids": [
        "CWE-285"
    ]
}
References

Affected packages

Git / github.com/openfga/openfga

Affected ranges

Type
GIT
Repo
https://github.com/openfga/openfga
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.3.0