CVE-2023-40579 is an authorization bypass vulnerability affecting OpenFGA versions 1.3.0 and earlier, specifically when using the ListObjects API with certain authorization models containing "rel1 from type1" expressions. This medium-severity vulnerability (CVSS 6.5) allows an authenticated attacker to gain high confidentiality impact without user interaction. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's no evidence of active exploitation or significant community discussion, affected users should upgrade to OpenFGA v1.3.1 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.1CPE matchmatch criteria | cpe:2.3:a:openfga:openfga:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.