CVE-2024-56323 is a critical authorization bypass vulnerability affecting OpenFGA versions 1.3.8 to 1.8.2, including associated Helm charts and Docker images. This flaw allows unauthorized access when specific conditions are met: the use of conditions in authorization models, contextual tuples containing conditions, and enabled query caching. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.38, < 0.2.19CPE matchmatch criteria | cpe:2.3:a:openfga:helm_charts:*:*:*:*:*:*:*:* | ||
>= 1.3.8, < 1.8.3CPE matchmatch criteria | cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.