Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/openfga/openfga: CVE-2025-25196 #3471

Closed
GoVulnBot opened this issue Feb 19, 2025 · 1 comment
Closed

Comments

@GoVulnBot
Copy link

Advisory CVE-2025-25196 references a vulnerability in the following Go modules:

Module
github.com/openfga/openfga

Description:
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA < v1.8.4 (Helm chart < openfga-0.2.22, docker < v.1.8.4) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users on OpenFGA v1.8.4 or previous, specifically under the following conditions are affected by this authorization bypass vulnerability: 1. Calling Check API or ListObjects with a model that has a relation directly assignable to both public access AND userset with the same type. 2. A type bound public access tu...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/openfga/openfga
      vulnerable_at: 1.8.5
summary: CVE-2025-25196 in github.com/openfga/openfga
cves:
    - CVE-2025-25196
references:
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-25196
    - fix: https://github.com/openfga/openfga/commit/0aee4f47e0c642de78831ceb27bb62b116f49588
    - web: https://github.com/openfga/openfga/security/advisories/GHSA-g4v5-6f5p-m38j
source:
    id: CVE-2025-25196
    created: 2025-02-19T22:01:17.872670743Z
review_status: UNREVIEWED

@thatnealpatel
Copy link
Member

Duplicate of #3470

@thatnealpatel thatnealpatel marked this as a duplicate of #3470 Feb 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants