GHSA-rxpw-85vw-fx87

Suggest an improvement
Source
https://github.com/advisories/GHSA-rxpw-85vw-fx87
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-rxpw-85vw-fx87/GHSA-rxpw-85vw-fx87.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-rxpw-85vw-fx87
Aliases
Related
Published
2024-01-26T20:12:00Z
Modified
2024-06-28T15:59:41.232492Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
OpenFGA denial of service
Details

Overview

OpenFGA is vulnerable to a DoS attack. In some scenarios that depend on the model and tuples used, a call to ListObjects may not release memory properly. So when a sufficiently high number of those calls are executed, the OpenFGA server can create an "out of memory" error and terminate.

Fix

Upgrade to v1.4.3. This upgrade is backwards compatible.

Database specific
{
    "nvd_published_at": "2024-01-26T17:15:13Z",
    "cwe_ids": [
        "CWE-401",
        "CWE-770"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-26T20:12:00Z"
}
References

Affected packages

Go / github.com/openfga/openfga

Package

Name
github.com/openfga/openfga
View open source insights on deps.dev
Purl
pkg:golang/github.com/openfga/openfga

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.3