{"id":"GHSA-8cph-m685-6v6r","summary":"OpenFGA Authorization Bypass","details":"# Overview\nSome end users of OpenFGA v1.5.0 or later are vulnerable to authorization bypass when calling Check or ListObjects APIs.\n\n# Am I Affected?\nYou are very likely affected if your model involves exclusion (e.g. `a but not b`) or intersection (e.g. `a and b`) and you have any cyclical relationships. If you are using these, please update as soon as possible.\n\n# Fix\nUpdate to v1.5.3\n\n# Backward Compatibility\nThis update is backward compatible.","aliases":["CVE-2024-31452","GO-2024-2729"],"modified":"2026-09-10T03:50:12.590459740Z","published":"2024-04-16T22:57:58Z","database_specific":{"nvd_published_at":"2024-04-16T22:15:35Z","cwe_ids":["CWE-285","CWE-863"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-04-16T22:57:58Z"},"references":[{"type":"WEB","url":"https://github.com/openfga/openfga/security/advisories/GHSA-8cph-m685-6v6r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31452"},{"type":"WEB","url":"https://github.com/openfga/openfga/commit/b6a6d99b2bdbf8c3781503989576076289f48ed2"},{"type":"PACKAGE","url":"https://github.com/openfga/openfga"}],"affected":[{"package":{"name":"github.com/openfga/openfga","ecosystem":"Go","purl":"pkg:golang/github.com/openfga/openfga"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.5.0"},{"fixed":"1.5.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-8cph-m685-6v6r/GHSA-8cph-m685-6v6r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}