CVE-2022-23542

Source
https://cve.org/CVERecord?id=CVE-2022-23542
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23542.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23542
Aliases
Published
2022-12-20T20:15:16.628Z
Modified
2026-07-15T01:49:09.333474355Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L CVSS Calculator
Summary
OpenFGA Authorization Bypass
Details

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible.

Database specific
{
    "cwe_ids": [
        "CWE-285"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23542.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/openfga/openfga

Affected ranges

Type
GIT
Repo
https://github.com/openfga/openfga
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "= 0.3.0"
        },
        {
            "last_affected": "= 0.3.0"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "0.3.1"
        }
    ],
    "cpe": "cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

= 0.*
= 0.3.0
v0.*
v0.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23542.json"