Vulnerability Database
Blog
FAQ
Docs
GO-2022-1080
See a problem?
Source
https://pkg.go.dev/vuln/GO-2022-1080
Import Source
https://vuln.go.dev/ID/GO-2022-1080.json
JSON Data
https://api.osv.dev/v1/vulns/GO-2022-1080
Aliases
CVE-2022-39341
GHSA-vj4m-83m8-xpw5
Published
2024-08-21T16:03:26Z
Modified
2024-08-21T16:28:36.412430Z
Summary
OpenFGA Authorization Bypass via tupleset wildcard in github.com/openfga/openfga
Details
OpenFGA Authorization Bypass via tupleset wildcard in github.com/openfga/openfga
References
https://github.com/openfga/openfga/security/advisories/GHSA-vj4m-83m8-xpw5
https://nvd.nist.gov/vuln/detail/CVE-2022-39341
https://github.com/openfga/openfga/commit/b466769cc100b2065047786578718d313f52695b
https://github.com/openfga/openfga/releases/tag/v0.2.4
Affected packages
Go
/
github.com/openfga/openfga
Package
Name
github.com/openfga/openfga
View open source insights on deps.dev
Purl
pkg:golang/github.com/openfga/openfga
Affected ranges
Type
SEMVER
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0.2.4
GO-2022-1080 - OSV