 
                        We found results for “”
CVE-2025-46331
Good to know:
 
                                    Date: April 30, 2025
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. This issue has been patched in version 1.8.11.
Severity Score
Related Resources (5)
Top Fix
 
                                    Upgrade Version
Upgrade to version github.com/openfga/openfga - v1.8.11;https://github.com/openfga/openfga.git - v1.8.11
CVSS v3.1
| Base Score: |  | 
|---|---|
| Attack Vector (AV): | NETWORK | 
| Attack Complexity (AC): | LOW | 
| Privileges Required (PR): | LOW | 
| User Interaction (UI): | NONE | 
| Scope (S): | CHANGED | 
| Confidentiality (C): | NONE | 
| Integrity (I): | NONE | 
| Availability (A): | NONE | 
 Vulnerabilities
                        Vulnerabilities
                 Projects
                        Projects
                 Vulnerability Disclosure
                        Vulnerability Disclosure
                 About Us
                    About Us
                 Contact Us
                    Contact Us
                

