CVE-2023-40579: Improper Access Control
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. Some end users of OpenFGA v1.3.0 or earlier is vulnerable to authorization bypass when calling the ListObjects API. The vulnerability affects customers using ListObjects
with specific models. The affected models contain expressions of type rel1 from type1
. This issue has been patched in version 1.3.1.
References
Detect and mitigate CVE-2023-40579 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →