During our internal security assessment, it was discovered that OpenFGA versions v0.3.0 is vulnerable to authorization bypass under certain conditions.
You are affected by this vulnerability if all of the following applies:
define viewer: [user]
document:1#viewer@user:jon
define viewer: [employee]
user=user:jon, relation=viewer, object:document:1
Upgrade to version v0.3.1
This update is backward compatible.
{ "nvd_published_at": "2022-12-20T21:15:00Z", "cwe_ids": [ "CWE-285" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-12-20T19:33:27Z" }