During our internal security assessment, it was discovered that OpenFGA versions v0.3.0 is vulnerable to authorization bypass under certain conditions.
You are affected by this vulnerability if all of the following applies:
define viewer: [user]document:1#viewer@user:jondefine viewer: [employee]user=user:jon, relation=viewer, object:document:1Upgrade to version v0.3.1
This update is backward compatible.
{
"nvd_published_at": "2022-12-20T21:15:00Z",
"severity": "HIGH",
"github_reviewed_at": "2022-12-20T19:33:27Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-285"
]
}