OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not
and from
expressions and a userset.
This fix is backward compatible.
{ "github_reviewed_at": "2024-08-09T21:23:26Z", "severity": "HIGH", "nvd_published_at": "2024-08-12T13:38:35Z", "github_reviewed": true, "cwe_ids": [ "CWE-285", "CWE-863" ] }